2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57104 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx. |
| CVE-2025-49089 | MEDIUM | 6.3 | 0.3% | Sep 15, 2025 | wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd... |
| CVE-2025-43792 | MEDIUM | 5.3 | 0.3% | Sep 15, 2025 | Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 202... |
| CVE-2025-59397 | MEDIUM | 5 | 0.4% | Sep 15, 2025 | Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection. |
| CVE-2025-56252 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted... |
| CVE-2025-52048 | MEDIUM | 6.5 | 0.2% | Sep 15, 2025 | In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py... |
| CVE-2025-8396 | MEDIUM | 6.9 | 0.4% | Sep 15, 2025 | Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o... |
| CVE-2025-59376 | MEDIUM | 5.3 | 0.3% | Sep 15, 2025 | feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ... |
| CVE-2025-39801 | MEDIUM | 5.5 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma... |
| CVE-2025-39800 | MEDIUM | 5.5 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio... |
| CVE-2025-43794 | MEDIUM | 4.8 | 0.2% | Sep 15, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported version... |
| CVE-2025-9826 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to caus... |
| CVE-2025-9084 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to... |
| CVE-2025-9072 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a... |
| CVE-2025-10441 | MEDIUM | 6.3 | 12.1% | Sep 15, 2025 | A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the... |
| CVE-2025-9078 | MEDIUM | 4.3 | 0.1% | Sep 15, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ... |
| CVE-2025-9076 | MEDIUM | 6.5 | 0.2% | Sep 15, 2025 | Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat... |
| CVE-2025-10440 | MEDIUM | 6.3 | 12.1% | Sep 15, 2025 | A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A... |
| CVE-2025-41713 | MEDIUM | 6.5 | 0.3% | Sep 15, 2025 | During a short time frame while the device is booting an unauthenticated remote attacker can send traffic to unauthorize... |
| CVE-2025-10433 | MEDIUM | 6.3 | 0.3% | Sep 15, 2025 | A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the ... |
| CVE-2025-59378 | MEDIUM | 5.7 | 0.1% | Sep 15, 2025 | In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program th... |
| CVE-2025-10453 | MEDIUM | 6.9 | 0.3% | Sep 15, 2025 | O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthent... |
| CVE-2025-10422 | MEDIUM | 4.3 | 0.3% | Sep 15, 2025 | A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the fun... |
| CVE-2025-59364 | MEDIUM | 5.3 | 0.4% | Sep 14, 2025 | The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth... |
| CVE-2025-10411 | MEDIUM | 6.1 | 0.3% | Sep 14, 2025 | A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affect... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now