2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31735 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in C. Johnson Footnot... |
| CVE-2025-31734 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Simple... |
| CVE-2025-31733 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boot Div WP Sitema... |
| CVE-2025-31732 | MEDIUM | 4.3 | 0.3% | Apr 1, 2025 | Missing Authorization vulnerability in gb-plugins GB Gallery Slideshow gb-gallery-slideshow allows Exploiting Incorrectl... |
| CVE-2025-31731 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Philip John Author... |
| CVE-2025-31730 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marke... |
| CVE-2025-31121 | MEDIUM | 5.4 | 12.1% | Apr 1, 2025 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.... |
| CVE-2025-30676 | MEDIUM | 6.1 | 59.3% | Apr 1, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue... |
| CVE-2025-30354 | MEDIUM | 4.3 | 0.3% | Apr 1, 2025 | Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to ... |
| CVE-2025-30224 | MEDIUM | 5.1 | 0.7% | Apr 1, 2025 | MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors ... |
| CVE-2025-30210 | MEDIUM | 6.1 | 0.3% | Apr 1, 2025 | Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which intern... |
| CVE-2025-3035 | MEDIUM | 5.3 | 0.3% | Apr 1, 2025 | By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab ... |
| CVE-2025-3031 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed... |
| CVE-2025-3028 | MEDIUM | 6.5 | 0.8% | Apr 1, 2025 | JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulner... |
| CVE-2025-31408 | MEDIUM | 4.3 | 0.2% | Apr 1, 2025 | Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-3084 | MEDIUM | 6.5 | 0.4% | Apr 1, 2025 | When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This ca... |
| CVE-2025-30177 | MEDIUM | 6.5 | 0.9% | Apr 1, 2025 | Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affe... |
| CVE-2025-2906 | MEDIUM | 6.4 | 0.3% | Apr 1, 2025 | The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versio... |
| CVE-2025-3082 | MEDIUM | 5.4 | 0.2% | Apr 1, 2025 | A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different o... |
| CVE-2025-29868 | MEDIUM | 6.5 | 0.8% | Apr 1, 2025 | Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: ... |
| CVE-2025-27427 | MEDIUM | 4.3 | 0.5% | Apr 1, 2025 | A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue pe... |
| CVE-2025-1512 | MEDIUM | 6.4 | 0.2% | Apr 1, 2025 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-1267 | MEDIUM | 5.5 | 0.3% | Apr 1, 2025 | The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions u... |
| CVE-2025-31409 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Co... |
| CVE-2025-30926 | MEDIUM | 4.3 | 0.3% | Apr 1, 2025 | Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons.This issue affects King Addo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now