2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43776MEDIUM5.4A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th...
CVE-2025-10107MEDIUM4.7A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown function of the file /...
CVE-2025-53609MEDIUM4.9A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2...
CVE-2025-47416MEDIUM5.9A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to u...
CVE-2025-33045MEDIUM6.7APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure...
CVE-2025-8008MEDIUM6.5A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a For...
CVE-2025-8007MEDIUM6.5A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent For...
CVE-2025-10095MEDIUM5.3A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically af...
CVE-2025-59019MEDIUM4.3Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0....
CVE-2025-59018MEDIUM6.5Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,...
CVE-2025-59016MEDIUM4.3Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0...
CVE-2025-59015MEDIUM6.5A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13....
CVE-2025-59013MEDIUM6.1An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11....
CVE-2025-40802MEDIUM4.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus...
CVE-2025-40757MEDIUM6.3A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2025-9542MEDIUM5.4The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP...
CVE-2025-9061MEDIUM6.4The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2025-9058MEDIUM6.4The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ...
CVE-2025-9489MEDIUM5The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions...
CVE-2025-43777MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024...
CVE-2025-43778MEDIUM6.1A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th...
CVE-2025-42938MEDIUM6.1Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could ...
CVE-2025-42930MEDIUM6.5SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting spec...
CVE-2025-42926MEDIUM5.3SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access inter...
CVE-2025-42925MEDIUM4.3Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now