2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24578 | MEDIUM | 5.4 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El... |
| CVE-2025-24575 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso HelloAss... |
| CVE-2025-24573 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softaculous PageLa... |
| CVE-2025-24572 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Re... |
| CVE-2025-24571 | MEDIUM | 5.4 | 0.4% | Jan 24, 2025 | Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Co... |
| CVE-2025-24568 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Requ... |
| CVE-2025-24552 | MEDIUM | 5.3 | 0.5% | Jan 24, 2025 | Generation of Error Message Containing Sensitive Information vulnerability in paytiumsupport Paytium paytium allows Retr... |
| CVE-2025-24547 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthias.wagner Ca... |
| CVE-2025-24546 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allow... |
| CVE-2025-24543 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allow... |
| CVE-2025-24542 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram ic... |
| CVE-2025-24025 | MEDIUM | 6.1 | 0.2% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-22610 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-22608 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-23991 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-cha... |
| CVE-2025-22607 | MEDIUM | 5.5 | 0.2% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0... |
| CVE-2025-0697 | MEDIUM | 6.9 | 0.5% | Jan 24, 2025 | A vulnerability, which was classified as problematic, was found in Telstra Smart Modem Gen 2 up to 20250115. This affect... |
| CVE-2025-0314 | MEDIUM | 6.1 | 0.4% | Jan 24, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.... |
| CVE-2025-0693 | MEDIUM | 6.9 | 0.4% | Jan 23, 2025 | Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques... |
| CVE-2025-24353 | MEDIUM | 4.3 | 0.4% | Jan 23, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing a... |
| CVE-2025-23227 | MEDIUM | 5.4 | 0.2% | Jan 23, 2025 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scriptin... |
| CVE-2025-0648 | MEDIUM | 4.9 | 0.5% | Jan 23, 2025 | Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highl... |
| CVE-2025-0619 | MEDIUM | 4.9 | 0.4% | Jan 23, 2025 | Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover ext... |
| CVE-2025-24530 | MEDIUM | 6.4 | 0.4% | Jan 23, 2025 | An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables fe... |
| CVE-2025-24529 | MEDIUM | 6.4 | 0.4% | Jan 23, 2025 | An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now