2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53571MEDIUM6.5Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect...
CVE-2025-53307HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Wor...
CVE-2025-49401CRITICAL9.8Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue af...
CVE-2025-48317HIGH7.5Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-...
CVE-2025-48105MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Ea...
CVE-2025-48104HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player al...
CVE-2025-48103MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mulscully Today's ...
CVE-2025-48102MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoi...
CVE-2025-32320HIGH7.8In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local esc...
CVE-2025-32318HIGH8.8In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of ...
CVE-2025-32317MEDIUM5.5In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information...
CVE-2025-32316MEDIUM5.5In gralloc4, there is a possible out of bounds write due to a missing bounds check. This could lead to local information...
CVE-2025-27003MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Si...
CVE-2025-26461LOW3.3In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u...
CVE-2025-26434MEDIUM5.5In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclo...
CVE-2025-10013MEDIUM6.3A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao...
CVE-2025-58780HIGH7.2index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by...
CVE-2025-10012HIGH8.8A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown functio...
CVE-2025-8695MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetG...
CVE-2025-58887MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | an...
CVE-2025-58886MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tan Nguyen Instant...
CVE-2025-58884MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivan Drago vipdrv ...
CVE-2025-58883MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Sear...
CVE-2025-58882MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Tex...
CVE-2025-58881HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simpl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now