2025 CVE Vulnerabilities
45,169 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41046 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41045 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41044 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41043 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41042 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41041 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41040 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41039 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41038 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41037 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41036 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack... |
| CVE-2025-41035 | MEDIUM | 6.5 | 0.6% | Sep 4, 2025 | A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/dow... |
| CVE-2025-9940 | MEDIUM | 5.4 | 0.3% | Sep 4, 2025 | A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the fil... |
| CVE-2025-9939 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an un... |
| CVE-2025-9937 | MEDIUM | 5.4 | 0.3% | Sep 4, 2025 | A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalSto... |
| CVE-2025-9936 | MEDIUM | 4.3 | 0.3% | Sep 4, 2025 | A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the f... |
| CVE-2025-9931 | MEDIUM | 6.1 | 0.3% | Sep 4, 2025 | A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!chang... |
| CVE-2025-9929 | MEDIUM | 4.8 | 0.3% | Sep 4, 2025 | A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file b... |
| CVE-2025-9616 | MEDIUM | 5.3 | 0.1% | Sep 4, 2025 | The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. ... |
| CVE-2025-9516 | MEDIUM | 4.9 | 0.4% | Sep 4, 2025 | The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 vi... |
| CVE-2025-9467 | MEDIUM | 5.3 | 0.4% | Sep 4, 2025 | When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass ... |
| CVE-2025-36909 | MEDIUM | 5.3 | 0.1% | Sep 4, 2025 | Information disclosure |
| CVE-2025-36908 | MEDIUM | 6.7 | 0.1% | Sep 4, 2025 | In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. ... |
| CVE-2025-36902 | MEDIUM | 6.7 | 0.1% | Sep 4, 2025 | In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overfl... |
| CVE-2025-36900 | MEDIUM | 6.7 | 0.1% | Sep 4, 2025 | In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lea... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now