2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22518MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Justi...
CVE-2025-22517MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson List Pag...
CVE-2025-22516MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hpinfosys Metadata...
CVE-2025-22515MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simon Show Google ...
CVE-2025-22512MEDIUM4.3Missing Authorization vulnerability in BoldGrid Help Scout help-scout allows Exploiting Incorrectly Configured Access Co...
CVE-2025-22511MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ella Van Durpe Sli...
CVE-2025-22503MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-deb...
CVE-2025-0297MEDIUM6.3A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability af...
CVE-2025-0246MEDIUM6.5When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android...
CVE-2025-0244MEDIUM5.3When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affecte...
CVE-2025-0243MEDIUM5.1Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs...
CVE-2025-0242MEDIUM6.5Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, a...
CVE-2025-0240MEDIUM4Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in...
CVE-2025-0239MEDIUM4When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure s...
CVE-2025-0238MEDIUM5.3Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially...
CVE-2025-0237MEDIUM5.4The WebChannel API, which is used to transport various information across processes, did not check the sending principal...
CVE-2025-0295MEDIUM5.4A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is...
CVE-2025-22362MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Bakovic WPA...
CVE-2025-22339MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in athemeart Store Co...
CVE-2025-22333MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piot...
CVE-2025-22327MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP...
CVE-2025-22323MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Image...
CVE-2025-22321MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TheInnovs Elements...
CVE-2025-22316MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addo...
CVE-2025-22315MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Typing...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now