2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9646 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organ... |
| CVE-2025-40709 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40708 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40707 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40706 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40705 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40704 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40703 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-40702 | MEDIUM | 5.4 | 0.2% | Aug 29, 2025 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura... |
| CVE-2025-9217 | MEDIUM | 6.5 | 0.5% | Aug 29, 2025 | The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 ... |
| CVE-2025-7383 | MEDIUM | 5.9 | 0.1% | Aug 29, 2025 | Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and... |
| CVE-2025-7071 | MEDIUM | 5.9 | 0.1% | Aug 29, 2025 | Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to ... |
| CVE-2025-4644 | MEDIUM | 5.3 | 0.4% | Aug 29, 2025 | A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A ... |
| CVE-2025-4643 | MEDIUM | 6.3 | 0.5% | Aug 29, 2025 | Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker wh... |
| CVE-2025-8150 | MEDIUM | 6.4 | 0.2% | Aug 29, 2025 | The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewr... |
| CVE-2025-54777 | MEDIUM | 5.3 | 0.1% | Aug 29, 2025 | Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai... |
| CVE-2025-9441 | MEDIUM | 6.5 | 0.3% | Aug 29, 2025 | The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all ve... |
| CVE-2025-9374 | MEDIUM | 4.3 | 0.1% | Aug 29, 2025 | The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-8619 | MEDIUM | 6.4 | 0.2% | Aug 29, 2025 | The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map ... |
| CVE-2025-8290 | MEDIUM | 6.4 | 0.2% | Aug 29, 2025 | The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver... |
| CVE-2025-8147 | MEDIUM | 4.3 | 0.2% | Aug 29, 2025 | The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th... |
| CVE-2025-9619 | MEDIUM | 6.9 | 0.3% | Aug 29, 2025 | A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of... |
| CVE-2025-39246 | MEDIUM | 5.3 | 0.4% | Aug 29, 2025 | There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated u... |
| CVE-2025-39245 | MEDIUM | 4.7 | 0.4% | Aug 29, 2025 | There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject e... |
| CVE-2025-9604 | MEDIUM | 6.3 | 0.2% | Aug 29, 2025 | A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now