2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22812 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aezaz Shaikh News ... |
| CVE-2025-22811 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristian Stan MT A... |
| CVE-2025-22810 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phi Phan Content B... |
| CVE-2025-22809 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theme funda PDF Ca... |
| CVE-2025-22808 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Surbma Surbma | Pr... |
| CVE-2025-22807 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Responsive ... |
| CVE-2025-22806 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio ... |
| CVE-2025-22805 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Skill ... |
| CVE-2025-22804 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author... |
| CVE-2025-22803 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Advance... |
| CVE-2025-22802 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email ... |
| CVE-2025-22801 | MEDIUM | 6.5 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes Free Woo... |
| CVE-2025-22561 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | Missing Authorization vulnerability in kbowson Title Experiments Free wp-experiments-free allows Exploiting Incorrectly ... |
| CVE-2025-0348 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issu... |
| CVE-2025-0342 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0. ... |
| CVE-2025-22445 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regardin... |
| CVE-2025-20033 | MEDIUM | 6.5 | 0.6% | Jan 9, 2025 | Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, w... |
| CVE-2025-0339 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown... |
| CVE-2025-0331 | MEDIUM | 6.9 | 0.5% | Jan 9, 2025 | A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the functi... |
| CVE-2025-22145 | MEDIUM | 6.3 | 0.7% | Jan 8, 2025 | Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale a... |
| CVE-2025-22143 | MEDIUM | 6.1 | 0.3% | Jan 8, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-0194 | MEDIUM | 6.5 | 0.5% | Jan 8, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 pr... |
| CVE-2025-22139 | MEDIUM | 6.1 | 0.3% | Jan 8, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-21111 | MEDIUM | 4.4 | 0.1% | Jan 8, 2025 | Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privil... |
| CVE-2025-20168 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now