2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1106 | MEDIUM | 6.5 | 0.9% | Feb 7, 2025 | A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/res... |
| CVE-2025-1105 | MEDIUM | 6.1 | 0.4% | Feb 7, 2025 | A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknow... |
| CVE-2025-1103 | MEDIUM | 6.5 | 11.3% | Feb 7, 2025 | A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the funct... |
| CVE-2025-25069 | MEDIUM | 6.5 | 0.7% | Feb 7, 2025 | A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" a... |
| CVE-2025-25168 | MEDIUM | 6.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-... |
| CVE-2025-25166 | MEDIUM | 6.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation inlocation allows Stored XSS.This issue aff... |
| CVE-2025-25160 | MEDIUM | 6.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker style-tweaker allows Stored XSS.This issue ... |
| CVE-2025-25146 | MEDIUM | 4.3 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in saleandro Songkick Concerts and Festivals songkick-concerts-and-festi... |
| CVE-2025-25145 | MEDIUM | 5.4 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in jordan.hatch Infusionsoft Analytics infusionsoft-web-tracker allows C... |
| CVE-2025-25143 | MEDIUM | 4.3 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ibasit GlobalQuran globalquran allows Cross Site Request Forgery.This... |
| CVE-2025-25136 | MEDIUM | 6.5 | 0.2% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shujahat21 Optimat... |
| CVE-2025-25120 | MEDIUM | 4.3 | 0.3% | Feb 7, 2025 | Missing Authorization vulnerability in Melodic Media Slide Banners slide-banners allows Exploiting Incorrectly Configure... |
| CVE-2025-25117 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Polonski Smar... |
| CVE-2025-25111 | MEDIUM | 5.4 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Cross Site Reques... |
| CVE-2025-25110 | MEDIUM | 5.4 | 0.3% | Feb 7, 2025 | Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorre... |
| CVE-2025-25105 | MEDIUM | 5.9 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop ... |
| CVE-2025-25103 | MEDIUM | 4.3 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bnielsen Indeed API indeed-api allows Cross Site Request Forgery.This... |
| CVE-2025-25098 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Links in... |
| CVE-2025-25097 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kwiliarty External... |
| CVE-2025-25096 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titusbicknell RSS ... |
| CVE-2025-25095 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reverbnationdev Re... |
| CVE-2025-25094 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amitythemes.com Br... |
| CVE-2025-25093 | MEDIUM | 6.1 | 0.2% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in paulswarthout Child Themes Helper child-themes-helper allows Path Tra... |
| CVE-2025-25091 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen... |
| CVE-2025-25085 | MEDIUM | 6.5 | 0.3% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matt_mcbrien WP Si... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now