2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23641 | MEDIUM | 6.5 | 0.3% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PowieT Powie's pLi... |
| CVE-2025-23639 | MEDIUM | 6.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows Sto... |
| CVE-2025-23514 | MEDIUM | 5.3 | 0.6% | Jan 16, 2025 | Missing Authorization vulnerability in Sanjay Prasad Loginplus loginplus allows Accessing Functionality Not Properly Con... |
| CVE-2025-23444 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nasir179125 Scroll... |
| CVE-2025-23434 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in viher3 Easy EU Coo... |
| CVE-2025-23423 | MEDIUM | 4.3 | 0.4% | Jan 16, 2025 | Missing Authorization vulnerability in Smackcoders Inc., SendGrid for WordPress wp-sendgrid-mailer allows Exploiting Inc... |
| CVE-2025-0518 | MEDIUM | 5.3 | 0.4% | Jan 16, 2025 | Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable.... |
| CVE-2025-0170 | MEDIUM | 6.1 | 0.3% | Jan 16, 2025 | The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and inc... |
| CVE-2025-0476 | MEDIUM | 4.3 | 0.4% | Jan 16, 2025 | Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an att... |
| CVE-2025-0215 | MEDIUM | 6.1 | 0.4% | Jan 15, 2025 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2025-0485 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown... |
| CVE-2025-0483 | MEDIUM | 4.6 | 0.3% | Jan 15, 2025 | A vulnerability has been found in Fanli2012 native-php-cms 1.0 and classified as problematic. This vulnerability affects... |
| CVE-2025-23040 | MEDIUM | 6.6 | 0.7% | Jan 15, 2025 | GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user t... |
| CVE-2025-0480 | MEDIUM | 4.3 | 0.5% | Jan 15, 2025 | A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file c... |
| CVE-2025-21083 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated use... |
| CVE-2025-20088 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate pos... |
| CVE-2025-20086 | MEDIUM | 6.5 | 0.4% | Jan 15, 2025 | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate pos... |
| CVE-2025-20036 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated use... |
| CVE-2025-22798 | MEDIUM | 6.5 | 0.2% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer Respo... |
| CVE-2025-22797 | MEDIUM | 6.5 | 0.2% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oğulcan Özügenç Ga... |
| CVE-2025-22788 | MEDIUM | 5.9 | 0.2% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codexpert, Inc CoD... |
| CVE-2025-22781 | MEDIUM | 6.5 | 0.2% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nativery Nativery ... |
| CVE-2025-22780 | MEDIUM | 6.5 | 0.2% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrey wp-pano wp-... |
| CVE-2025-22779 | MEDIUM | 4.3 | 0.2% | Jan 15, 2025 | Missing Authorization vulnerability in codeaffairs WP News Sliders wp-news-sliders allows Exploiting Incorrectly Configu... |
| CVE-2025-22773 | MEDIUM | 5.3 | 0.3% | Jan 15, 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WP Chill Htaccess File ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now