2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22618 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-... |
| CVE-2025-22617 | MEDIUM | 6.1 | 0.3% | Jan 13, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-22616 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-... |
| CVE-2025-22615 | MEDIUM | 6.1 | 0.3% | Jan 13, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-22614 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-... |
| CVE-2025-22613 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-... |
| CVE-2025-22138 | MEDIUM | 5.1 | 0.4% | Jan 13, 2025 | @codidact/qpixel is a Q&A-based community knowledge-sharing software. In affected versions when a category is set to pri... |
| CVE-2025-22134 | MEDIUM | 5.5 | 0.4% | Jan 13, 2025 | When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer ... |
| CVE-2025-23027 | MEDIUM | 6.3 | 0.3% | Jan 13, 2025 | next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.exam... |
| CVE-2025-23026 | MEDIUM | 6.1 | 0.3% | Jan 13, 2025 | jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTM... |
| CVE-2025-22142 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can a... |
| CVE-2025-22828 | MEDIUM | 4.3 | 1.9% | Jan 13, 2025 | CloudStack users can add and read comments (annotations) on resources they are authorised to access. Due to an access ... |
| CVE-2025-0404 | MEDIUM | 6.3 | 0.3% | Jan 13, 2025 | A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the fu... |
| CVE-2025-0403 | MEDIUM | 6.9 | 0.5% | Jan 13, 2025 | A vulnerability, which was classified as problematic, has been found in 1902756969 reggie 1.0. Affected by this issue is... |
| CVE-2025-0401 | MEDIUM | 6.9 | 1.2% | Jan 13, 2025 | A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the... |
| CVE-2025-0400 | MEDIUM | 5.4 | 0.3% | Jan 12, 2025 | A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unkno... |
| CVE-2025-0398 | MEDIUM | 5.1 | 0.3% | Jan 12, 2025 | A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is... |
| CVE-2025-0397 | MEDIUM | 5.3 | 0.4% | Jan 12, 2025 | A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown functio... |
| CVE-2025-23109 | MEDIUM | 6.5 | 0.2% | Jan 11, 2025 | Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This v... |
| CVE-2025-23108 | MEDIUM | 4.3 | 0.2% | Jan 11, 2025 | Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofi... |
| CVE-2025-0106 | MEDIUM | 5.3 | 0.5% | Jan 11, 2025 | A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate file... |
| CVE-2025-0104 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malic... |
| CVE-2025-23112 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users t... |
| CVE-2025-23111 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redire... |
| CVE-2025-23110 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject fiel... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now