2025 CVE Vulnerabilities
45,165 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9881 | MEDIUM | 6.1 | 0.1% | Sep 12, 2025 | The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-9880 | MEDIUM | 6.1 | 0.1% | Sep 12, 2025 | The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-9879 | MEDIUM | 6.4 | 0.2% | Sep 12, 2025 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s... |
| CVE-2025-9877 | MEDIUM | 6.4 | 0.2% | Sep 12, 2025 | The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' sh... |
| CVE-2025-43789 | MEDIUM | 5.3 | 0.2% | Sep 12, 2025 | JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through... |
| CVE-2025-43788 | MEDIUM | 4.3 | 0.2% | Sep 12, 2025 | The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.... |
| CVE-2025-10274 | MEDIUM | 6.1 | 0.3% | Sep 12, 2025 | A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the fi... |
| CVE-2025-10273 | MEDIUM | 5.3 | 0.7% | Sep 12, 2025 | A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f... |
| CVE-2025-10272 | MEDIUM | 6.1 | 0.3% | Sep 11, 2025 | A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. T... |
| CVE-2025-10271 | MEDIUM | 6.1 | 0.3% | Sep 11, 2025 | A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The mani... |
| CVE-2025-9214 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited devi... |
| CVE-2025-58364 | MEDIUM | 6.5 | 1.1% | Sep 11, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 ... |
| CVE-2025-58065 | MEDIUM | 6.5 | 0.4% | Sep 11, 2025 | Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to... |
| CVE-2025-43782 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2... |
| CVE-2025-40300 | MEDIUM | 5.5 | 0.3% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCA... |
| CVE-2025-39791 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: dm: dm-crypt: Do not partially accept write BIOs wi... |
| CVE-2025-39789 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: x86/aegis - Add missing error checks The s... |
| CVE-2025-39787 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: soc: qcom: mdt_loader: Ensure we don't read past th... |
| CVE-2025-39785 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix irq_request()'s irq name v... |
| CVE-2025-39784 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI: Fix link speed calculation on retrain failure ... |
| CVE-2025-39782 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: jbd2: prevent softlockup in jbd2_log_do_checkpoint(... |
| CVE-2025-39781 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: parisc: Drop WARN_ON_ONCE() from flush_cache_vmap ... |
| CVE-2025-39780 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched/ext: Fix invalid task state transitions on cl... |
| CVE-2025-39779 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: subpage: keep TOWRITE tag until folio is cle... |
| CVE-2025-39777 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - Fix CFI failure due to type punning... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now