2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30875 | MEDIUM | 5.9 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger W... |
| CVE-2025-8712 | MEDIUM | 5.4 | 0.4% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-8711 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before... |
| CVE-2025-55146 | MEDIUM | 4.9 | 0.7% | Sep 9, 2025 | An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivan... |
| CVE-2025-55144 | MEDIUM | 5.4 | 0.5% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-55143 | MEDIUM | 6.1 | 0.7% | Sep 9, 2025 | Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivant... |
| CVE-2025-55139 | MEDIUM | 6.8 | 0.8% | Sep 9, 2025 | SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before... |
| CVE-2025-52277 | MEDIUM | 6.1 | 0.4% | Sep 9, 2025 | Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted pa... |
| CVE-2025-43776 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th... |
| CVE-2025-10107 | MEDIUM | 4.7 | 3.9% | Sep 9, 2025 | A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown function of the file /... |
| CVE-2025-53609 | MEDIUM | 4.9 | 8.4% | Sep 9, 2025 | A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2... |
| CVE-2025-47416 | MEDIUM | 5.9 | 0.3% | Sep 9, 2025 | A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to u... |
| CVE-2025-33045 | MEDIUM | 6.7 | 0.1% | Sep 9, 2025 | APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure... |
| CVE-2025-8008 | MEDIUM | 6.5 | 0.6% | Sep 9, 2025 | A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a For... |
| CVE-2025-8007 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent For... |
| CVE-2025-10095 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically af... |
| CVE-2025-59019 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.... |
| CVE-2025-59018 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,... |
| CVE-2025-59016 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0... |
| CVE-2025-59015 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.... |
| CVE-2025-59013 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.... |
| CVE-2025-40802 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus... |
| CVE-2025-40757 | MEDIUM | 6.3 | 0.3% | Sep 9, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2025-9542 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-9061 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now