2025 CVE Vulnerabilities
45,160 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52344 | MEDIUM | 6.1 | 0.3% | Sep 15, 2025 | Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject ... |
| CVE-2025-43791 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0... |
| CVE-2025-59328 | MEDIUM | 6.5 | 0.6% | Sep 15, 2025 | A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the ins... |
| CVE-2025-59155 | MEDIUM | 6.9 | 0.3% | Sep 15, 2025 | hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4... |
| CVE-2025-58177 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scriptin... |
| CVE-2025-58172 | MEDIUM | 5.3 | 0.4% | Sep 15, 2025 | drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vu... |
| CVE-2025-57176 | MEDIUM | 6.5 | 0.4% | Sep 15, 2025 | On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip... |
| CVE-2025-57104 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx. |
| CVE-2025-49089 | MEDIUM | 6.3 | 0.3% | Sep 15, 2025 | wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd... |
| CVE-2025-43792 | MEDIUM | 5.3 | 0.3% | Sep 15, 2025 | Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 202... |
| CVE-2025-59397 | MEDIUM | 5 | 0.4% | Sep 15, 2025 | Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection. |
| CVE-2025-56252 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted... |
| CVE-2025-52048 | MEDIUM | 6.5 | 0.2% | Sep 15, 2025 | In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py... |
| CVE-2025-8396 | MEDIUM | 6.9 | 0.4% | Sep 15, 2025 | Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o... |
| CVE-2025-59376 | MEDIUM | 5.3 | 0.3% | Sep 15, 2025 | feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ... |
| CVE-2025-39801 | MEDIUM | 5.5 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma... |
| CVE-2025-39800 | MEDIUM | 5.5 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio... |
| CVE-2025-43794 | MEDIUM | 4.8 | 0.2% | Sep 15, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported version... |
| CVE-2025-9826 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to caus... |
| CVE-2025-9084 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to... |
| CVE-2025-9072 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a... |
| CVE-2025-10441 | MEDIUM | 6.3 | 12.1% | Sep 15, 2025 | A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the... |
| CVE-2025-9078 | MEDIUM | 4.3 | 0.1% | Sep 15, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ... |
| CVE-2025-9076 | MEDIUM | 6.5 | 0.2% | Sep 15, 2025 | Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat... |
| CVE-2025-10440 | MEDIUM | 6.3 | 12.1% | Sep 15, 2025 | A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now