2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1748 | MEDIUM | 4.7 | 0.2% | Feb 28, 2025 | HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to mod... |
| CVE-2025-1747 | MEDIUM | 4.7 | 0.2% | Feb 28, 2025 | HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to mod... |
| CVE-2025-1746 | MEDIUM | 6.1 | 0.2% | Feb 28, 2025 | Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute... |
| CVE-2025-22271 | MEDIUM | 6.9 | 0.4% | Feb 28, 2025 | The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For"... |
| CVE-2025-1300 | MEDIUM | 6.1 | 0.2% | Feb 28, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2025-22492 | MEDIUM | 6.3 | 0.2% | Feb 28, 2025 | The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this str... |
| CVE-2025-22491 | MEDIUM | 6.7 | 0.2% | Feb 28, 2025 | The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application... |
| CVE-2025-1662 | MEDIUM | 6.4 | 0.3% | Feb 28, 2025 | The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl... |
| CVE-2025-1560 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The WOW Entrance Effects (WEE!) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wee'... |
| CVE-2025-1571 | MEDIUM | 5.4 | 0.3% | Feb 28, 2025 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's An... |
| CVE-2025-1405 | MEDIUM | 5.4 | 0.3% | Feb 28, 2025 | The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_produ... |
| CVE-2025-0764 | MEDIUM | 6.5 | 0.3% | Feb 28, 2025 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the '... |
| CVE-2025-1513 | MEDIUM | 6.1 | 0.3% | Feb 28, 2025 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str... |
| CVE-2025-1511 | MEDIUM | 6.1 | 0.3% | Feb 28, 2025 | The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln... |
| CVE-2025-1506 | MEDIUM | 4.3 | 0.2% | Feb 28, 2025 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ... |
| CVE-2025-1757 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2025-1505 | MEDIUM | 6.1 | 0.3% | Feb 28, 2025 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' p... |
| CVE-2025-0801 | MEDIUM | 4.3 | 0.2% | Feb 28, 2025 | The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-23225 | MEDIUM | 6.5 | 0.4% | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the im... |
| CVE-2025-0823 | MEDIUM | 6.5 | 0.5% | Feb 28, 2025 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse direc... |
| CVE-2025-25728 | MEDIUM | 6.5 | 0.2% | Feb 28, 2025 | Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send commu... |
| CVE-2025-25727 | MEDIUM | 6.2 | 0.2% | Feb 28, 2025 | Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store pass... |
| CVE-2025-1681 | MEDIUM | 5.4 | 0.3% | Feb 28, 2025 | The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing c... |
| CVE-2025-24832 | MEDIUM | 5.5 | 0.2% | Feb 27, 2025 | Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products a... |
| CVE-2025-25730 | MEDIUM | 4.6 | 0.2% | Feb 27, 2025 | An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now