2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43784 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024... |
| CVE-2025-10209 | MEDIUM | 5.4 | 0.3% | Sep 10, 2025 | A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the com... |
| CVE-2025-57520 | MEDIUM | 6.1 | 0.3% | Sep 10, 2025 | A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and d... |
| CVE-2025-43785 | MEDIUM | 6.1 | 0.2% | Sep 10, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 ... |
| CVE-2025-8681 | MEDIUM | 5.4 | 0.2% | Sep 10, 2025 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requi... |
| CVE-2025-59035 | MEDIUM | 5.4 | 0.2% | Sep 10, 2025 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t... |
| CVE-2025-59034 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t... |
| CVE-2025-57573 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi... |
| CVE-2025-57572 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentC... |
| CVE-2025-57571 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT... |
| CVE-2025-57570 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS. |
| CVE-2025-57569 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT. |
| CVE-2025-43938 | MEDIUM | 4.4 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnera... |
| CVE-2025-43886 | MEDIUM | 4.4 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerabili... |
| CVE-2025-43884 | MEDIUM | 6.7 | 0.5% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele... |
| CVE-2025-29592 | MEDIUM | 5.6 | 0.4% | Sep 10, 2025 | oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. |
| CVE-2025-20248 | MEDIUM | 6 | 0.1% | Sep 10, 2025 | A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to byp... |
| CVE-2025-20159 | MEDIUM | 5.3 | 0.3% | Sep 10, 2025 | A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could ... |
| CVE-2025-56578 | MEDIUM | 5.7 | 0.3% | Sep 10, 2025 | An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the... |
| CVE-2025-10227 | MEDIUM | 4.6 | 0.1% | Sep 10, 2025 | Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2... |
| CVE-2025-10221 | MEDIUM | 5.5 | 0.1% | Sep 10, 2025 | Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet ... |
| CVE-2025-40725 | MEDIUM | 5.1 | 0.3% | Sep 10, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute J... |
| CVE-2025-36758 | MEDIUM | 6.3 | 0.5% | Sep 10, 2025 | It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Pas... |
| CVE-2025-36757 | MEDIUM | 6.3 | 0.3% | Sep 10, 2025 | It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to byp... |
| CVE-2025-36756 | MEDIUM | 5.8 | 0.3% | Sep 10, 2025 | A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now