2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9215 | MEDIUM | 6.5 | 0.6% | Sep 17, 2025 | The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor... |
| CVE-2025-9203 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl... |
| CVE-2025-9818 | MEDIUM | 6.7 | 0.1% | Sep 17, 2025 | A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided ... |
| CVE-2025-55075 | MEDIUM | 6.9 | 0.3% | Sep 17, 2025 | Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled ... |
| CVE-2025-10584 | MEDIUM | 5.4 | 0.3% | Sep 17, 2025 | A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/... |
| CVE-2025-10188 | MEDIUM | 5.4 | 0.1% | Sep 17, 2025 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio... |
| CVE-2025-10125 | MEDIUM | 6.4 | 0.3% | Sep 17, 2025 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shor... |
| CVE-2025-9891 | MEDIUM | 4.3 | 0.2% | Sep 17, 2025 | The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9851 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar... |
| CVE-2025-9629 | MEDIUM | 4.3 | 0.2% | Sep 17, 2025 | The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5... |
| CVE-2025-8394 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_producti... |
| CVE-2025-8153 | MEDIUM | 5.1 | 0.3% | Sep 17, 2025 | Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8... |
| CVE-2025-10166 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter'... |
| CVE-2025-10050 | MEDIUM | 6.6 | 0.8% | Sep 17, 2025 | The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t... |
| CVE-2025-43804 | MEDIUM | 6.1 | 0.2% | Sep 16, 2025 | Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP ... |
| CVE-2025-37131 | MEDIUM | 4.9 | 0.3% | Sep 16, 2025 | A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to acc... |
| CVE-2025-37130 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitr... |
| CVE-2025-37129 | MEDIUM | 6.7 | 0.2% | Sep 16, 2025 | A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi... |
| CVE-2025-37128 | MEDIUM | 6.8 | 0.3% | Sep 16, 2025 | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote a... |
| CVE-2025-9708 | MEDIUM | 6.8 | 0.3% | Sep 16, 2025 | A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c... |
| CVE-2025-43805 | MEDIUM | 5.3 | 0.3% | Sep 16, 2025 | Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92... |
| CVE-2025-10566 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unkno... |
| CVE-2025-49728 | MEDIUM | 4 | 0.2% | Sep 16, 2025 | Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security ... |
| CVE-2025-47967 | MEDIUM | 4.7 | 0.3% | Sep 16, 2025 | Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform... |
| CVE-2025-54237 | MEDIUM | 5.5 | 0.2% | Sep 16, 2025 | Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now