2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0751 | MEDIUM | 6.5 | 0.5% | Jan 27, 2025 | A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_Bit... |
| CVE-2025-24354 | MEDIUM | 5.3 | 0.8% | Jan 27, 2025 | imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even wi... |
| CVE-2025-23197 | MEDIUM | 6.5 | 0.4% | Jan 27, 2025 | matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6... |
| CVE-2025-0733 | MEDIUM | 4.5 | 0.2% | Jan 27, 2025 | A vulnerability, which was classified as problematic, was found in Postman up to 11.20 on Windows. This affects an unkno... |
| CVE-2025-0732 | MEDIUM | 4.5 | 0.2% | Jan 27, 2025 | A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by t... |
| CVE-2025-0730 | MEDIUM | 6.3 | 0.7% | Jan 27, 2025 | A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected ... |
| CVE-2025-0729 | MEDIUM | 6.9 | 0.4% | Jan 27, 2025 | A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This i... |
| CVE-2025-24747 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0. |
| CVE-2025-24744 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | Missing Authorization vulnerability in NotFound Bridge Core. This issue affects Bridge Core: from n/a through 3.3. |
| CVE-2025-24743 | MEDIUM | 4.3 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a thro... |
| CVE-2025-24741 | MEDIUM | 6.1 | 0.2% | Jan 27, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in LOGON KB Support kb-support.This issue affects KB S... |
| CVE-2025-24740 | MEDIUM | 4.7 | 0.2% | Jan 27, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ThimPress LearnPress learnpress.This issue affects ... |
| CVE-2025-24689 | MEDIUM | 5.9 | 0.3% | Jan 27, 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Javier Carazo Import an... |
| CVE-2025-24680 | MEDIUM | 6.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPExperts.io WP Multistor... |
| CVE-2025-24662 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-24653 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Conf... |
| CVE-2025-24628 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.Th... |
| CVE-2025-24606 | MEDIUM | 6.4 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In... |
| CVE-2025-24603 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Print Barcode Labels for your WooCommerce produ... |
| CVE-2025-24600 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through... |
| CVE-2025-24593 | MEDIUM | 6.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser ... |
| CVE-2025-24590 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in picu picu picu allows Exploiting Incorrectly Configured Access Control Security L... |
| CVE-2025-24540 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by S... |
| CVE-2025-24538 | MEDIUM | 5.4 | 0.2% | Jan 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allo... |
| CVE-2025-24537 | MEDIUM | 5.4 | 0.2% | Jan 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site R... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now