2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2869 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could... |
| CVE-2025-2868 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could... |
| CVE-2025-31096 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima... |
| CVE-2025-31094 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Po... |
| CVE-2025-31093 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redpixelstudios RP... |
| CVE-2025-31090 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown ... |
| CVE-2025-31088 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Paid Me... |
| CVE-2025-31083 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZEEN101 Leaky Payw... |
| CVE-2025-31079 | MEDIUM | 4.3 | 0.1% | Mar 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven usermaven allows Cross Site Request Forgery.This ... |
| CVE-2025-31077 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ul... |
| CVE-2025-31076 | MEDIUM | 4.9 | 0.2% | Mar 28, 2025 | Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Server ... |
| CVE-2025-31075 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayment... |
| CVE-2025-31073 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bensibley Unlimite... |
| CVE-2025-27001 | MEDIUM | 6.5 | 0.3% | Mar 28, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A complete shipping solution fo... |
| CVE-2025-27716 | MEDIUM | 6.5 | 0.6% | Mar 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing p... |
| CVE-2025-27567 | MEDIUM | 5.4 | 0.2% | Mar 28, 2025 | Cross-site scripting vulnerability exists in the NickName registration screen of HGW-BL1500HM Ver 002.002.003 and earlie... |
| CVE-2025-1705 | MEDIUM | 6.1 | 0.3% | Mar 28, 2025 | The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-2578 | MEDIUM | 5.3 | 0.3% | Mar 28, 2025 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosu... |
| CVE-2025-2074 | MEDIUM | 5.3 | 0.4% | Mar 28, 2025 | The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to generic SQL Injection via the ‘sSearch’ parameter in... |
| CVE-2025-31335 | MEDIUM | 4 | 0.2% | Mar 28, 2025 | The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML... |
| CVE-2025-2804 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2025-2027 | MEDIUM | 5.9 | 0.1% | Mar 28, 2025 | A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered... |
| CVE-2025-1762 | MEDIUM | 4.3 | 0.2% | Mar 28, 2025 | The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its ... |
| CVE-2025-2894 | MEDIUM | 6.6 | 0.7% | Mar 28, 2025 | The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an u... |
| CVE-2025-31092 | MEDIUM | 6.5 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now