2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53799 | MEDIUM | 5.5 | 0.7% | Sep 9, 2025 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information local... |
| CVE-2025-53798 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53797 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53796 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53348 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-53340 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive... |
| CVE-2025-53291 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a thro... |
| CVE-2025-49860 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Su... |
| CVE-2025-47997 | MEDIUM | 5.3 | 0.8% | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an auth... |
| CVE-2025-47437 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue af... |
| CVE-2025-39553 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th... |
| CVE-2025-39541 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affe... |
| CVE-2025-39523 | MEDIUM | 4.7 | 0.2% | Sep 9, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects... |
| CVE-2025-32688 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Targ... |
| CVE-2025-30875 | MEDIUM | 5.9 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger W... |
| CVE-2025-8712 | MEDIUM | 5.4 | 0.4% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-8711 | MEDIUM | 5.4 | 0.3% | Sep 9, 2025 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before... |
| CVE-2025-55146 | MEDIUM | 4.9 | 0.7% | Sep 9, 2025 | An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivan... |
| CVE-2025-55144 | MEDIUM | 5.4 | 0.5% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-55143 | MEDIUM | 6.1 | 0.7% | Sep 9, 2025 | Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivant... |
| CVE-2025-55139 | MEDIUM | 6.8 | 0.8% | Sep 9, 2025 | SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before... |
| CVE-2025-52277 | MEDIUM | 6.1 | 0.4% | Sep 9, 2025 | Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted pa... |
| CVE-2025-43776 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th... |
| CVE-2025-10107 | MEDIUM | 4.7 | 3.9% | Sep 9, 2025 | A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown function of the file /... |
| CVE-2025-53609 | MEDIUM | 4.9 | 8.4% | Sep 9, 2025 | A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now