2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53575HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Pri...
CVE-2025-53347MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium kalium allows Cross Site Request Forgery.This issue ...
CVE-2025-53343MEDIUM4.3Missing Authorization vulnerability in GoodLayers Modernize modernize allows Exploiting Incorrectly Configured Access Co...
CVE-2025-53342MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Moderni...
CVE-2025-53341MEDIUM4.3Missing Authorization vulnerability in Themovation App, SaaS & Software Startup Tech Theme - Stratus stratusx allows Exp...
CVE-2025-53330MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate WP Rental...
CVE-2025-53249MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Reques...
CVE-2025-53241MEDIUM5.5Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified simplified allows Server Side Request Forgery.Th...
CVE-2025-53221MEDIUM4.3Missing Authorization vulnerability in codeablepress CodeablePress codeablepress-simple-frontend-profile-picture-upload ...
CVE-2025-53219MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows ...
CVE-2025-52797HIGH8.2Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affe...
CVE-2025-52771MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bcupham Video Expa...
CVE-2025-52769MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery flexo-social-gallery allows Cross Si...
CVE-2025-52767MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analyt...
CVE-2025-52765HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analyt...
CVE-2025-8974CRITICAL9.8A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality ...
CVE-2025-8973CRITICAL9.8A vulnerability has been found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the file...
CVE-2025-8972CRITICAL9.8A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unk...
CVE-2025-52335MEDIUM6.1EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive inform...
CVE-2025-51986HIGH7.5An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to ...
CVE-2025-21110MEDIUM4.4Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerability. A high ...
CVE-2025-9043MEDIUM6.7The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin p...
CVE-2025-9039MEDIUM5.3We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accesse...
CVE-2025-8971CRITICAL9.8A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects ...
CVE-2025-8970CRITICAL9.8A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now