2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10002 | MEDIUM | 4.9 | 0.3% | Sep 20, 2025 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is... |
| CVE-2025-10652 | MEDIUM | 6.5 | 0.3% | Sep 20, 2025 | The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-net... |
| CVE-2025-43808 | MEDIUM | 5.3 | 0.3% | Sep 19, 2025 | The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1... |
| CVE-2025-9081 | MEDIUM | 6.5 | 0.3% | Sep 19, 2025 | Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authe... |
| CVE-2025-59689 | MEDIUM | 6.1 | 1.9% | Sep 19, 2025 | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a ... |
| CVE-2025-57396 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework ... |
| CVE-2025-56762 | MEDIUM | 6.1 | 0.3% | Sep 19, 2025 | Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php. |
| CVE-2025-43809 | MEDIUM | 4.3 | 0.2% | Sep 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 throug... |
| CVE-2025-43803 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.... |
| CVE-2025-26517 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege es... |
| CVE-2025-26516 | MEDIUM | 5.3 | 0.4% | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Se... |
| CVE-2025-26514 | MEDIUM | 6.4 | 0.2% | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cr... |
| CVE-2025-10722 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file Andr... |
| CVE-2025-10721 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknow... |
| CVE-2025-36248 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated use... |
| CVE-2025-57296 | MEDIUM | 6.5 | 3.3% | Sep 19, 2025 | Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which proc... |
| CVE-2025-56869 | MEDIUM | 5.3 | 0.7% | Sep 19, 2025 | Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write a... |
| CVE-2025-55910 | MEDIUM | 6.3 | 0.2% | Sep 19, 2025 | CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php. |
| CVE-2025-39865 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: tee: fix NULL pointer dereference in tee_shm_put t... |
| CVE-2025-39858 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: eth: mlx4: Fix IS_ERR() vs NULL check bug in mlx4_e... |
| CVE-2025-39857 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib... |
| CVE-2025-39856 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix null pointer... |
| CVE-2025-39852 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix socket memory leak in TCP-AO failure h... |
| CVE-2025-39851 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD when refreshing an FDB entry with a ... |
| CVE-2025-39850 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix NPD in {arp,neigh}_reduce() when using n... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now