2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23079 | MEDIUM | 6.1 | 0.2% | Jan 10, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-23078 | MEDIUM | 6.5 | 0.2% | Jan 10, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-22600 | MEDIUM | 6.5 | 0.4% | Jan 10, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-22599 | MEDIUM | 6.5 | 0.4% | Jan 10, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-22598 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in ... |
| CVE-2025-22597 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in ... |
| CVE-2025-22596 | MEDIUM | 6.5 | 0.3% | Jan 10, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-23022 | MEDIUM | 6.2 | 0.2% | Jan 10, 2025 | FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c. |
| CVE-2025-0311 | MEDIUM | 5.4 | 0.3% | Jan 10, 2025 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Ta... |
| CVE-2025-21380 | MEDIUM | 6.5 | 1.5% | Jan 9, 2025 | Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. |
| CVE-2025-21385 | MEDIUM | 6.5 | 24.4% | Jan 9, 2025 | A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose inform... |
| CVE-2025-21596 | MEDIUM | 6.8 | 0.2% | Jan 9, 2025 | An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS... |
| CVE-2025-21592 | MEDIUM | 6.8 | 0.2% | Jan 9, 2025 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Junip... |
| CVE-2025-22827 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joomag WP Joomag w... |
| CVE-2025-22826 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Sell D... |
| CVE-2025-22824 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lucia.intelisano L... |
| CVE-2025-22823 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jtwerdy Genesis St... |
| CVE-2025-22822 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bishawjit-das wp c... |
| CVE-2025-22821 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vfthemes StorePres... |
| CVE-2025-22820 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in goldsounds VR View... |
| CVE-2025-22819 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roberto Bottalico ... |
| CVE-2025-22818 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S3Bubble S3Player ... |
| CVE-2025-22817 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profil... |
| CVE-2025-22815 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Button Bl... |
| CVE-2025-22813 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conve... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now