2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57900 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit g... |
| CVE-2025-57899 | MEDIUM | 5.3 | 0.4% | Sep 22, 2025 | Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Accessing Functionality Not... |
| CVE-2025-57898 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Vega WP Front... |
| CVE-2025-57685 | HIGH | 8.8 | 1.4% | Sep 22, 2025 | The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B... |
| CVE-2025-55887 | MEDIUM | 6.1 | 0.4% | Sep 22, 2025 | Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in... |
| CVE-2025-53570 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SE... |
| CVE-2025-53469 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mortgage Calculato... |
| CVE-2025-53468 | HIGH | 8.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.c... |
| CVE-2025-53467 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Login-Lo... |
| CVE-2025-53466 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Better Fi... |
| CVE-2025-53465 | HIGH | 7.2 | 0.6% | Sep 22, 2025 | Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This ... |
| CVE-2025-53464 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Online Optimisatio... |
| CVE-2025-53463 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega... |
| CVE-2025-53462 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SAPO SAPO Feed sap... |
| CVE-2025-53461 | MEDIUM | 4.4 | 0.2% | Sep 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Binsaifullah Beaf image-compare-block allows Server Side Request For... |
| CVE-2025-53460 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Affili... |
| CVE-2025-53459 | — | — | — | Sep 22, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-53458 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davaxi Goracash go... |
| CVE-2025-53457 | MEDIUM | 4.4 | 0.3% | Sep 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Serv... |
| CVE-2025-53456 | MEDIUM | 4.3 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross... |
| CVE-2025-53455 | MEDIUM | 5.9 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CashBill CashBill.... |
| CVE-2025-53454 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimat... |
| CVE-2025-53452 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | Missing Authorization vulnerability in Barry Event Rocket allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2025-53451 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cros... |
| CVE-2025-53450 | HIGH | 7.5 | 0.6% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now