2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57884 | MEDIUM | 4.3 | 0.2% | Aug 22, 2025 | Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting ... |
| CVE-2025-9341 | MEDIUM | 5.9 | 0.1% | Aug 22, 2025 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ... |
| CVE-2025-8678 | MEDIUM | 5.9 | 0.3% | Aug 22, 2025 | The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via... |
| CVE-2025-41452 | MEDIUM | 6.8 | 0.2% | Aug 22, 2025 | Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Ser... |
| CVE-2025-43752 | MEDIUM | 6.5 | 0.3% | Aug 22, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-43753 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2... |
| CVE-2025-43747 | MEDIUM | 6.5 | 0.2% | Aug 21, 2025 | A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure... |
| CVE-2025-55229 | MEDIUM | 5.3 | 0.4% | Aug 21, 2025 | Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoo... |
| CVE-2025-55107 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11... |
| CVE-2025-55106 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t... |
| CVE-2025-55105 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t... |
| CVE-2025-55104 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenti... |
| CVE-2025-55103 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t... |
| CVE-2025-27714 | MEDIUM | 6.3 | 0.3% | Aug 21, 2025 | An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unaut... |
| CVE-2025-24489 | MEDIUM | 6.3 | 0.3% | Aug 21, 2025 | An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to s... |
| CVE-2025-38742 | MEDIUM | 5.3 | 0.1% | Aug 21, 2025 | Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Res... |
| CVE-2025-57768 | MEDIUM | 6.9 | 0.4% | Aug 21, 2025 | Phproject is a high performance full-featured project management system. From 1.8.0 to before 1.8.3, a Stored Cross-Site... |
| CVE-2025-43754 | MEDIUM | 5.3 | 0.2% | Aug 21, 2025 | Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.... |
| CVE-2025-8402 | MEDIUM | 4.9 | 0.3% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to ... |
| CVE-2025-7969 | MEDIUM | 6.1 | 0.2% | Aug 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it... |
| CVE-2025-6465 | MEDIUM | 4.3 | 0.7% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names... |
| CVE-2025-57763 | MEDIUM | 6.1 | 0.2% | Aug 21, 2025 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Reflected Cross-Site Scripting (XSS) vuln... |
| CVE-2025-57762 | MEDIUM | 6.1 | 0.2% | Aug 21, 2025 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Stored Cross-Site Scripting (XSS) vulnera... |
| CVE-2025-55522 | MEDIUM | 6.5 | 0.4% | Aug 21, 2025 | Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execu... |
| CVE-2025-55521 | MEDIUM | 6.5 | 0.4% | Aug 21, 2025 | An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now