2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9384 | MEDIUM | 5.5 | 0.2% | Aug 24, 2025 | A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /s... |
| CVE-2025-9382 | MEDIUM | 6.4 | 0.2% | Aug 24, 2025 | A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability affects unknown code of t... |
| CVE-2025-8208 | MEDIUM | 6.4 | 0.2% | Aug 24, 2025 | The Spexo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countd... |
| CVE-2025-9131 | MEDIUM | 6.4 | 0.2% | Aug 23, 2025 | The Ogulo – 360° Tour plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all ... |
| CVE-2025-8062 | MEDIUM | 6.4 | 0.2% | Aug 23, 2025 | The WS Theme Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ws_weather shortc... |
| CVE-2025-7957 | MEDIUM | 6.4 | 0.2% | Aug 23, 2025 | The ShortcodeHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_link_target’ paramete... |
| CVE-2025-7842 | MEDIUM | 4.3 | 0.1% | Aug 23, 2025 | The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-7841 | MEDIUM | 4.3 | 0.1% | Aug 23, 2025 | The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Reque... |
| CVE-2025-7839 | MEDIUM | 4.3 | 0.1% | Aug 23, 2025 | The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-7828 | MEDIUM | 4.3 | 0.2% | Aug 23, 2025 | The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2025-7827 | MEDIUM | 4.3 | 0.2% | Aug 23, 2025 | The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due t... |
| CVE-2025-7821 | MEDIUM | 5.3 | 0.2% | Aug 23, 2025 | The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2025-43765 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 20... |
| CVE-2025-43764 | MEDIUM | 6.5 | 0.3% | Aug 23, 2025 | Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScrip... |
| CVE-2025-43767 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131,... |
| CVE-2025-43769 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 thr... |
| CVE-2025-43770 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024... |
| CVE-2025-52450 | MEDIUM | 6.5 | 0.4% | Aug 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve... |
| CVE-2025-43761 | MEDIUM | 6.1 | 0.2% | Aug 22, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024... |
| CVE-2025-54812 | MEDIUM | 5.4 | 1.1% | Aug 22, 2025 | Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not p... |
| CVE-2025-50859 | MEDIUM | 6.1 | 0.3% | Aug 22, 2025 | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows aut... |
| CVE-2025-50858 | MEDIUM | 6.1 | 0.2% | Aug 22, 2025 | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allow... |
| CVE-2025-43762 | MEDIUM | 6.5 | 0.4% | Aug 22, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-43758 | MEDIUM | 5.3 | 0.3% | Aug 22, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-43760 | MEDIUM | 5.4 | 0.2% | Aug 22, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now