2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58982 | MEDIUM | 5.9 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline'... |
| CVE-2025-58981 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker ... |
| CVE-2025-58980 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Acc... |
| CVE-2025-58979 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-58978 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Inco... |
| CVE-2025-58977 | MEDIUM | 4.9 | 0.1% | Sep 9, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Ser... |
| CVE-2025-58976 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker ... |
| CVE-2025-58975 | MEDIUM | 4.3 | 0.1% | Sep 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re... |
| CVE-2025-57540 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter confi... |
| CVE-2025-57539 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Vir... |
| CVE-2025-57538 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of P... |
| CVE-2025-55226 | MEDIUM | 6.7 | 0.4% | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an... |
| CVE-2025-55225 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-54917 | MEDIUM | 4.3 | 0.8% | Sep 9, 2025 | Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a... |
| CVE-2025-54915 | MEDIUM | 6.7 | 0.5% | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ... |
| CVE-2025-54901 | MEDIUM | 5.5 | 0.6% | Sep 9, 2025 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2025-54252 | MEDIUM | 5.4 | 4.6% | Sep 9, 2025 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability... |
| CVE-2025-54251 | MEDIUM | 4.3 | 1.6% | Sep 9, 2025 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result ... |
| CVE-2025-54250 | MEDIUM | 4.9 | 0.4% | Sep 9, 2025 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c... |
| CVE-2025-54249 | MEDIUM | 6.5 | 1.8% | Sep 9, 2025 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabilit... |
| CVE-2025-54247 | MEDIUM | 6.5 | 0.4% | Sep 9, 2025 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c... |
| CVE-2025-54246 | MEDIUM | 6.5 | 0.4% | Sep 9, 2025 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that cou... |
| CVE-2025-54109 | MEDIUM | 6.7 | 0.4% | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ... |
| CVE-2025-54107 | MEDIUM | 4.3 | 0.9% | Sep 9, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea... |
| CVE-2025-54104 | MEDIUM | 6.7 | 0.4% | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now