2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0368 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting i... |
| CVE-2025-24982 | MEDIUM | 4.3 | 0.2% | Feb 4, 2025 | Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a ma... |
| CVE-2025-24029 | MEDIUM | 5.3 | 0.3% | Feb 3, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymo... |
| CVE-2025-23210 | MEDIUM | 4.8 | 0.4% | Feb 3, 2025 | phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been fo... |
| CVE-2025-22129 | MEDIUM | 4.3 | 0.3% | Feb 3, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an... |
| CVE-2025-24961 | MEDIUM | 6 | 0.5% | Feb 3, 2025 | org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backend... |
| CVE-2025-25065 | MEDIUM | 5.3 | 0.6% | Feb 3, 2025 | SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1... |
| CVE-2025-24898 | MEDIUM | 6.3 | 0.6% | Feb 3, 2025 | rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_prot... |
| CVE-2025-24697 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gal... |
| CVE-2025-24643 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Con... |
| CVE-2025-24642 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Explo... |
| CVE-2025-24639 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Greys Korea for WooCommerce korea-for-woocommerce all... |
| CVE-2025-24559 | MEDIUM | 6.1 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails... |
| CVE-2025-23747 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nitesh Awesome Tim... |
| CVE-2025-23581 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio ... |
| CVE-2025-23561 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robertkay MLL Audi... |
| CVE-2025-23527 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | Missing Authorization vulnerability in hemnathmouli WC Wallet wc-wallet allows Accessing Functionality Not Properly Cons... |
| CVE-2025-22701 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-e... |
| CVE-2025-22695 | MEDIUM | 4.3 | 0.4% | Feb 3, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue af... |
| CVE-2025-22694 | MEDIUM | 4.3 | 0.3% | Feb 3, 2025 | Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerc... |
| CVE-2025-22686 | MEDIUM | 5.3 | 0.4% | Feb 3, 2025 | Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploi... |
| CVE-2025-22683 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Notifi... |
| CVE-2025-22681 | MEDIUM | 4.3 | 0.3% | Feb 3, 2025 | Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly... |
| CVE-2025-22677 | MEDIUM | 4.8 | 0.3% | Feb 3, 2025 | Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured A... |
| CVE-2025-22292 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Pow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now