2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9058 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2025-9489 | MEDIUM | 5 | 0.3% | Sep 9, 2025 | The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions... |
| CVE-2025-43777 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024... |
| CVE-2025-43778 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th... |
| CVE-2025-42938 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could ... |
| CVE-2025-42930 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting spec... |
| CVE-2025-42926 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access inter... |
| CVE-2025-42925 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticate... |
| CVE-2025-42923 | MEDIUM | 4.3 | 0.1% | Sep 9, 2025 | Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked b... |
| CVE-2025-42920 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attack... |
| CVE-2025-42918 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauth... |
| CVE-2025-42917 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated us... |
| CVE-2025-42915 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic use... |
| CVE-2025-42912 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, re... |
| CVE-2025-42911 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could... |
| CVE-2025-10121 | MEDIUM | 6.3 | 0.2% | Sep 9, 2025 | A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipul... |
| CVE-2025-10117 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the fi... |
| CVE-2025-43763 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP... |
| CVE-2025-58752 | MEDIUM | 5.3 | 0.6% | Sep 8, 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files o... |
| CVE-2025-58751 | MEDIUM | 5.3 | 1.2% | Sep 8, 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w... |
| CVE-2025-58452 | MEDIUM | 6.1 | 0.2% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-57815 | MEDIUM | 6.5 | 0.3% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies ... |
| CVE-2025-57766 | MEDIUM | 4.8 | 0.3% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d... |
| CVE-2025-53838 | MEDIUM | 5.4 | 0.2% | Sep 8, 2025 | LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove... |
| CVE-2025-43722 | MEDIUM | 6.7 | 0.1% | Sep 8, 2025 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now