2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23849 | MEDIUM | 5.4 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in bpiwowar PAPERCITE papercite allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-23669 | MEDIUM | 6.5 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nurul Amin WP Smar... |
| CVE-2025-23656 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects... |
| CVE-2025-23529 | MEDIUM | 6.5 | 0.4% | Jan 27, 2025 | Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Accessing Functionality Not Properly Co... |
| CVE-2025-24754 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0. |
| CVE-2025-24584 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting... |
| CVE-2025-24533 | MEDIUM | 5.4 | 0.1% | Jan 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Cross Sit... |
| CVE-2025-0696 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash o... |
| CVE-2025-0695 | MEDIUM | 5.3 | 0.3% | Jan 27, 2025 | An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an... |
| CVE-2025-24814 | MEDIUM | 5.5 | 1.1% | Jan 27, 2025 | Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) us... |
| CVE-2025-24390 | MEDIUM | 6.8 | 0.2% | Jan 27, 2025 | A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes... |
| CVE-2025-24389 | MEDIUM | 6.3 | 0.1% | Jan 27, 2025 | Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log... |
| CVE-2025-0721 | MEDIUM | 6.1 | 0.5% | Jan 27, 2025 | A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image... |
| CVE-2025-0720 | MEDIUM | 5.5 | 0.2% | Jan 26, 2025 | A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by th... |
| CVE-2025-0350 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2025-24361 | MEDIUM | 5.3 | 0.3% | Jan 25, 2025 | Nuxt is an open-source web development framework for Vue.js. Source code may be stolen during dev when using version 3.0... |
| CVE-2025-24360 | MEDIUM | 5.3 | 0.5% | Jan 25, 2025 | Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt... |
| CVE-2025-21262 | MEDIUM | 5.4 | 0.4% | Jan 24, 2025 | User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2025-0710 | MEDIUM | 5.4 | 0.4% | Jan 24, 2025 | A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unk... |
| CVE-2025-0709 | MEDIUM | 4.8 | 0.4% | Jan 24, 2025 | A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown pr... |
| CVE-2025-0708 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown... |
| CVE-2025-0706 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problem... |
| CVE-2025-24363 | MEDIUM | 4.2 | 0.2% | Jan 24, 2025 | The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.8.9, in CI... |
| CVE-2025-0705 | MEDIUM | 6.1 | 0.4% | Jan 24, 2025 | A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as pr... |
| CVE-2025-0704 | MEDIUM | 6.9 | 0.7% | Jan 24, 2025 | A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now