2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30768 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mlaza jAlbum Bridg... |
| CVE-2025-30767 | MEDIUM | 5.4 | 0.3% | Mar 27, 2025 | Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configu... |
| CVE-2025-30766 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy... |
| CVE-2025-30764 | MEDIUM | 4.3 | 0.2% | Mar 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool football-pool allows Cross Site Request Forger... |
| CVE-2025-30763 | MEDIUM | 6.5 | 0.3% | Mar 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP... |
| CVE-2025-29993 | MEDIUM | 5.3 | 0.3% | Mar 27, 2025 | The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affecte... |
| CVE-2025-2685 | MEDIUM | 5.4 | 0.2% | Mar 27, 2025 | The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-0273 | MEDIUM | 5.5 | 0.1% | Mar 27, 2025 | HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be ... |
| CVE-2025-31165 | MEDIUM | 6.9 | 0.3% | Mar 27, 2025 | Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows att... |
| CVE-2025-2835 | MEDIUM | 5.3 | 0.3% | Mar 27, 2025 | A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulner... |
| CVE-2025-2833 | MEDIUM | 6.9 | 0.7% | Mar 27, 2025 | A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknow... |
| CVE-2025-2832 | MEDIUM | 5.3 | 0.3% | Mar 27, 2025 | A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 an... |
| CVE-2025-2481 | MEDIUM | 6.1 | 0.3% | Mar 27, 2025 | The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id' parameter in all version... |
| CVE-2025-20230 | MEDIUM | 6.5 | 0.3% | Mar 26, 2025 | In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk S... |
| CVE-2025-30407 | MEDIUM | 6.3 | 0.1% | Mar 26, 2025 | Local privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber P... |
| CVE-2025-2838 | MEDIUM | 6.5 | 0.2% | Mar 26, 2025 | Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows n... |
| CVE-2025-20232 | MEDIUM | 5.7 | 0.4% | Mar 26, 2025 | In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2... |
| CVE-2025-20231 | MEDIUM | 5.7 | 0.5% | Mar 26, 2025 | In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk S... |
| CVE-2025-20228 | MEDIUM | 6.5 | 0.2% | Mar 26, 2025 | In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.2.2403.108, and 9... |
| CVE-2025-20227 | MEDIUM | 4.3 | 0.4% | Mar 26, 2025 | In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.10... |
| CVE-2025-20226 | MEDIUM | 5.7 | 0.4% | Mar 26, 2025 | In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107... |
| CVE-2025-29322 | MEDIUM | 4.6 | 0.2% | Mar 26, 2025 | A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary... |
| CVE-2025-30352 | MEDIUM | 5.3 | 0.3% | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and p... |
| CVE-2025-30351 | MEDIUM | 4.3 | 0.3% | Mar 26, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior t... |
| CVE-2025-2600 | MEDIUM | 6.8 | 0.4% | Mar 26, 2025 | Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticate... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now