2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20167 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ... |
| CVE-2025-20166 | MEDIUM | 5.4 | 0.4% | Jan 8, 2025 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ... |
| CVE-2025-20126 | MEDIUM | 4.8 | 0.2% | Jan 8, 2025 | A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could all... |
| CVE-2025-20123 | MEDIUM | 4.8 | 0.3% | Jan 8, 2025 | Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an auth... |
| CVE-2025-21102 | MEDIUM | 4.4 | 0.2% | Jan 8, 2025 | Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privil... |
| CVE-2025-22215 | MEDIUM | 4.3 | 0.2% | Jan 8, 2025 | VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization... |
| CVE-2025-21603 | MEDIUM | 4.8 | 0.3% | Jan 8, 2025 | Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to th... |
| CVE-2025-22132 | MEDIUM | 4.8 | 0.4% | Jan 7, 2025 | WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the fil... |
| CVE-2025-0301 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | A vulnerability, which was classified as problematic, has been found in code-projects Online Book Shop 1.0. Affected by ... |
| CVE-2025-22621 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `a... |
| CVE-2025-22500 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Ali Alpha Pric... |
| CVE-2025-22365 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 ... |
| CVE-2025-22363 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in Hermann LAHAMI Allada T-shirt Designer for Woocommerce allada-tshirt-designer-for... |
| CVE-2025-22354 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Themes Digi S... |
| CVE-2025-22334 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FilaThemes Educati... |
| CVE-2025-22319 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media S... |
| CVE-2025-22306 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Spencer Haws Link Whisp... |
| CVE-2025-22296 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Hash El... |
| CVE-2025-22591 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in 8blocks 1003 Mortgage Application 1003-mortgage-application allows Exploiting Inc... |
| CVE-2025-22585 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Ultimate ... |
| CVE-2025-22584 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Timel... |
| CVE-2025-22581 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bytephp Arcade Rea... |
| CVE-2025-22580 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Auto IT Biltorvet ... |
| CVE-2025-22579 | MEDIUM | 5.9 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arefly WP Header N... |
| CVE-2025-22578 | MEDIUM | 5.9 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aazztech WP Cookie... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now