2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0630 | MEDIUM | 6.5 | 0.4% | Feb 4, 2025 | Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (L... |
| CVE-2025-0509 | MEDIUM | 6.8 | 0.8% | Feb 4, 2025 | A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with anoth... |
| CVE-2025-24373 | MEDIUM | 6.5 | 0.4% | Feb 4, 2025 | woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF inv... |
| CVE-2025-0451 | MEDIUM | 6.3 | 0.3% | Feb 4, 2025 | Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who con... |
| CVE-2025-0445 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-0444 | MEDIUM | 6.3 | 0.3% | Feb 4, 2025 | Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2025-23059 | MEDIUM | 4.9 | 0.6% | Feb 4, 2025 | A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directori... |
| CVE-2025-24598 | MEDIUM | 6.1 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails... |
| CVE-2025-22730 | MEDIUM | 6.5 | 0.3% | Feb 4, 2025 | Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-22697 | MEDIUM | 5.4 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon... |
| CVE-2025-22696 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Docu... |
| CVE-2025-22675 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Alert Box... |
| CVE-2025-22674 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Produc... |
| CVE-2025-22664 | MEDIUM | 4.8 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
| CVE-2025-22662 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPuls... |
| CVE-2025-22653 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv Music Pres... |
| CVE-2025-22643 | MEDIUM | 4.3 | 0.2% | Feb 4, 2025 | Missing Authorization vulnerability in famethemes OnePress onepress allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-22642 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites Dynami... |
| CVE-2025-22641 | MEDIUM | 5.9 | 0.2% | Feb 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Not... |
| CVE-2025-22206 | MEDIUM | 4.7 | 8.7% | Feb 4, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (admi... |
| CVE-2025-0825 | MEDIUM | 5.3 | 0.4% | Feb 4, 2025 | cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null... |
| CVE-2025-1019 | MEDIUM | 4.3 | 0.3% | Feb 4, 2025 | The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be l... |
| CVE-2025-1018 | MEDIUM | 5.3 | 0.4% | Feb 4, 2025 | The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have b... |
| CVE-2025-1015 | MEDIUM | 5.4 | 1.3% | Feb 4, 2025 | The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and exp... |
| CVE-2025-1013 | MEDIUM | 6.5 | 0.3% | Feb 4, 2025 | A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have result... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now