2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53571 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect... |
| CVE-2025-53307 | HIGH | 7.1 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Wor... |
| CVE-2025-49401 | CRITICAL | 9.8 | 0.4% | Sep 5, 2025 | Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue af... |
| CVE-2025-48317 | HIGH | 7.5 | 0.4% | Sep 5, 2025 | Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-... |
| CVE-2025-48105 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Ea... |
| CVE-2025-48104 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player al... |
| CVE-2025-48103 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mulscully Today's ... |
| CVE-2025-48102 | MEDIUM | 5.9 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoi... |
| CVE-2025-32320 | HIGH | 7.8 | 0.1% | Sep 5, 2025 | In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local esc... |
| CVE-2025-32318 | HIGH | 8.8 | 0.3% | Sep 5, 2025 | In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of ... |
| CVE-2025-32317 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information... |
| CVE-2025-32316 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | In gralloc4, there is a possible out of bounds write due to a missing bounds check. This could lead to local information... |
| CVE-2025-27003 | MEDIUM | 4.3 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Si... |
| CVE-2025-26461 | LOW | 3.3 | 0.1% | Sep 5, 2025 | In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u... |
| CVE-2025-26434 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclo... |
| CVE-2025-10013 | MEDIUM | 6.3 | 0.3% | Sep 5, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao... |
| CVE-2025-58780 | HIGH | 7.2 | 0.2% | Sep 5, 2025 | index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by... |
| CVE-2025-10012 | HIGH | 8.8 | 0.4% | Sep 5, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown functio... |
| CVE-2025-8695 | MEDIUM | 5.4 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetG... |
| CVE-2025-58887 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | an... |
| CVE-2025-58886 | MEDIUM | 5.9 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tan Nguyen Instant... |
| CVE-2025-58884 | MEDIUM | 5.9 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ivan Drago vipdrv ... |
| CVE-2025-58883 | MEDIUM | 5.9 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thomas Harris Sear... |
| CVE-2025-58882 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in w1zzard Simple Tex... |
| CVE-2025-58881 | HIGH | 8.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simpl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now