2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43886 | MEDIUM | 4.4 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerabili... |
| CVE-2025-43884 | MEDIUM | 6.7 | 0.5% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele... |
| CVE-2025-29592 | MEDIUM | 5.6 | 0.4% | Sep 10, 2025 | oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. |
| CVE-2025-20248 | MEDIUM | 6 | 0.1% | Sep 10, 2025 | A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to byp... |
| CVE-2025-20159 | MEDIUM | 5.3 | 0.3% | Sep 10, 2025 | A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could ... |
| CVE-2025-56578 | MEDIUM | 5.7 | 0.3% | Sep 10, 2025 | An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the... |
| CVE-2025-10227 | MEDIUM | 4.6 | 0.1% | Sep 10, 2025 | Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2... |
| CVE-2025-10222 | MEDIUM | 4.8 | 0.1% | Sep 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon... |
| CVE-2025-10221 | MEDIUM | 6.7 | 0.1% | Sep 10, 2025 | Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet ... |
| CVE-2025-40725 | MEDIUM | 5.1 | 0.3% | Sep 10, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute J... |
| CVE-2025-36758 | MEDIUM | 6.3 | 0.5% | Sep 10, 2025 | It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Pas... |
| CVE-2025-36757 | MEDIUM | 6.3 | 0.3% | Sep 10, 2025 | It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to byp... |
| CVE-2025-36756 | MEDIUM | 5.8 | 0.3% | Sep 10, 2025 | A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t... |
| CVE-2025-9979 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin... |
| CVE-2025-9888 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2025-9857 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-9622 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-9463 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v... |
| CVE-2025-9367 | MEDIUM | 5.5 | 0.2% | Sep 10, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up... |
| CVE-2025-8778 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-7843 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u... |
| CVE-2025-7826 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions ... |
| CVE-2025-6189 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter ... |
| CVE-2025-10142 | MEDIUM | 4.9 | 0.4% | Sep 10, 2025 | The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa... |
| CVE-2025-10126 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now