2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43776 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th... |
| CVE-2025-10107 | MEDIUM | 4.7 | 3.9% | Sep 9, 2025 | A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown function of the file /... |
| CVE-2025-53609 | MEDIUM | 4.9 | 8.4% | Sep 9, 2025 | A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2... |
| CVE-2025-47416 | MEDIUM | 5.9 | 0.3% | Sep 9, 2025 | A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to u... |
| CVE-2025-33045 | MEDIUM | 6.7 | 0.1% | Sep 9, 2025 | APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure... |
| CVE-2025-8008 | MEDIUM | 6.5 | 0.6% | Sep 9, 2025 | A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a For... |
| CVE-2025-8007 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent For... |
| CVE-2025-10095 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically af... |
| CVE-2025-59019 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.... |
| CVE-2025-59018 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,... |
| CVE-2025-59016 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0... |
| CVE-2025-59015 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.... |
| CVE-2025-59013 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.... |
| CVE-2025-40802 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus... |
| CVE-2025-40757 | MEDIUM | 6.3 | 0.3% | Sep 9, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2025-9542 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-9061 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2025-9058 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and ... |
| CVE-2025-9489 | MEDIUM | 5 | 0.3% | Sep 9, 2025 | The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions... |
| CVE-2025-43777 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024... |
| CVE-2025-43778 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th... |
| CVE-2025-42938 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could ... |
| CVE-2025-42930 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting spec... |
| CVE-2025-42926 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access inter... |
| CVE-2025-42925 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticate... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now