2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10822 | MEDIUM | 4.3 | 0.3% | Sep 23, 2025 | A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle... |
| CVE-2025-43814 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, ... |
| CVE-2025-43810 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.11... |
| CVE-2025-10821 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of ... |
| CVE-2025-10820 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top... |
| CVE-2025-10819 | MEDIUM | 4.3 | 0.4% | Sep 22, 2025 | A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC... |
| CVE-2025-43806 | MEDIUM | 4.3 | 0.2% | Sep 22, 2025 | Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2... |
| CVE-2025-59535 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-57205 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content... |
| CVE-2025-57204 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulne... |
| CVE-2025-47910 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than in... |
| CVE-2025-59433 | MEDIUM | 5.3 | 0.2% | Sep 22, 2025 | Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to ve... |
| CVE-2025-59432 | MEDIUM | 6.6 | 0.8% | Sep 22, 2025 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L... |
| CVE-2025-57203 | MEDIUM | 4.8 | 0.2% | Sep 22, 2025 | MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feat... |
| CVE-2025-9960 | MEDIUM | 6.9 | 0.4% | Sep 22, 2025 | A restriction bypass vulnerability in is-localhost-ip could allow attackers to perform Server-Side Request Forgery (SSRF... |
| CVE-2025-59592 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Acosta Ma... |
| CVE-2025-59591 | MEDIUM | 4.3 | 0.2% | Sep 22, 2025 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-59590 | MEDIUM | 5.9 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi... |
| CVE-2025-59589 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soleda... |
| CVE-2025-59587 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2025-59586 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2025-59585 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2025-59584 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2025-59583 | MEDIUM | 6.5 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2025-59582 | MEDIUM | 5.3 | 0.7% | Sep 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now