2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55054 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55053 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | CWE-328: Use of Weak Hash |
| CVE-2025-54255 | MEDIUM | 4 | 0.2% | Sep 9, 2025 | Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Desig... |
| CVE-2025-47415 | MEDIUM | 6.8 | 0.4% | Sep 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x7... |
| CVE-2025-43786 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q... |
| CVE-2025-36125 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This v... |
| CVE-2025-36011 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or se... |
| CVE-2025-34175 | MEDIUM | 6.1 | 14.8% | Sep 9, 2025 | In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed ... |
| CVE-2025-34174 | MEDIUM | 5.4 | 9.8% | Sep 9, 2025 | In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a nume... |
| CVE-2025-34173 | MEDIUM | 4.3 | 0.8% | Sep 9, 2025 | In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct... |
| CVE-2025-34172 | MEDIUM | 6.1 | 1.0% | Sep 9, 2025 | In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed af... |
| CVE-2025-55052 | MEDIUM | 4.3 | 0.3% | Sep 9, 2025 | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2025-43781 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q... |
| CVE-2025-43775 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 thr... |
| CVE-2025-9269 | MEDIUM | 6.9 | 0.3% | Sep 9, 2025 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark dev... |
| CVE-2025-57665 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, cr... |
| CVE-2025-5500 | MEDIUM | 5.3 | 0.1% | Sep 9, 2025 | A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file Andr... |
| CVE-2025-59005 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-58990 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLento... |
| CVE-2025-58989 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 D... |
| CVE-2025-58988 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tick... |
| CVE-2025-58987 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football ... |
| CVE-2025-58985 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition... |
| CVE-2025-58984 | MEDIUM | 5.9 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welca... |
| CVE-2025-58983 | MEDIUM | 5.9 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Incl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now