2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43756 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | <!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerabi... |
| CVE-2025-43755 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, ... |
| CVE-2025-9308 | MEDIUM | 5.5 | 0.2% | Aug 21, 2025 | A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/... |
| CVE-2025-9306 | MEDIUM | 5.4 | 0.3% | Aug 21, 2025 | A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown... |
| CVE-2025-9162 | MEDIUM | 4.9 | 0.5% | Aug 21, 2025 | A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes pla... |
| CVE-2025-57753 | MEDIUM | 6 | 0.4% | Aug 21, 2025 | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible... |
| CVE-2025-55744 | MEDIUM | 4.3 | 0.1% | Aug 21, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some ... |
| CVE-2025-55742 | MEDIUM | 4.8 | 0.3% | Aug 21, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPi... |
| CVE-2025-55371 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers... |
| CVE-2025-50860 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers ... |
| CVE-2025-55367 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attacke... |
| CVE-2025-55366 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily... |
| CVE-2025-51818 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute ar... |
| CVE-2025-47184 | MEDIUM | 5.3 | 0.2% | Aug 21, 2025 | An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 ... |
| CVE-2025-8064 | MEDIUM | 6.4 | 0.2% | Aug 21, 2025 | The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ parame... |
| CVE-2025-8023 | MEDIUM | 4.9 | 0.4% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path trave... |
| CVE-2025-49810 | MEDIUM | 4.3 | 0.2% | Aug 21, 2025 | Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre... |
| CVE-2025-49222 | MEDIUM | 6.8 | 0.3% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to ... |
| CVE-2025-47870 | MEDIUM | 4.3 | 0.2% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team in... |
| CVE-2025-36530 | MEDIUM | 4.9 | 0.5% | Aug 21, 2025 | Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate fi... |
| CVE-2025-8607 | MEDIUM | 6.4 | 0.2% | Aug 21, 2025 | The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-7221 | MEDIUM | 4.3 | 0.2% | Aug 21, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2025-53505 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabil... |
| CVE-2025-53504 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vuln... |
| CVE-2025-48355 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now