2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22518 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Justi... |
| CVE-2025-22517 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson List Pag... |
| CVE-2025-22516 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hpinfosys Metadata... |
| CVE-2025-22515 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simon Show Google ... |
| CVE-2025-22512 | MEDIUM | 4.3 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in BoldGrid Help Scout help-scout allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-22511 | MEDIUM | 6.5 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ella Van Durpe Sli... |
| CVE-2025-22503 | MEDIUM | 4.3 | 0.2% | Jan 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-deb... |
| CVE-2025-0297 | MEDIUM | 6.3 | 0.6% | Jan 7, 2025 | A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability af... |
| CVE-2025-0246 | MEDIUM | 6.5 | 0.4% | Jan 7, 2025 | When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android... |
| CVE-2025-0244 | MEDIUM | 5.3 | 6.6% | Jan 7, 2025 | When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affecte... |
| CVE-2025-0243 | MEDIUM | 5.1 | 0.2% | Jan 7, 2025 | Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs... |
| CVE-2025-0242 | MEDIUM | 6.5 | 13.1% | Jan 7, 2025 | Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, a... |
| CVE-2025-0240 | MEDIUM | 4 | 0.7% | Jan 7, 2025 | Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in... |
| CVE-2025-0239 | MEDIUM | 4 | 0.2% | Jan 7, 2025 | When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure s... |
| CVE-2025-0238 | MEDIUM | 5.3 | 0.8% | Jan 7, 2025 | Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially... |
| CVE-2025-0237 | MEDIUM | 5.4 | 0.6% | Jan 7, 2025 | The WebChannel API, which is used to transport various information across processes, did not check the sending principal... |
| CVE-2025-0295 | MEDIUM | 5.4 | 0.4% | Jan 7, 2025 | A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is... |
| CVE-2025-22362 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Bakovic WPA... |
| CVE-2025-22339 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in athemeart Store Co... |
| CVE-2025-22333 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piot... |
| CVE-2025-22327 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP... |
| CVE-2025-22323 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Image... |
| CVE-2025-22321 | MEDIUM | 6.5 | 0.2% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TheInnovs Elements... |
| CVE-2025-22316 | MEDIUM | 5.4 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addo... |
| CVE-2025-22315 | MEDIUM | 5.4 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Typing... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now