2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51990 | MEDIUM | 4.8 | 0.5% | Aug 20, 2025 | XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administra... |
| CVE-2025-50864 | MEDIUM | 6.5 | 0.4% | Aug 20, 2025 | An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharin... |
| CVE-2025-43748 | MEDIUM | 6.8 | 0.1% | Aug 20, 2025 | Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 202... |
| CVE-2025-1142 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at... |
| CVE-2025-1139 | MEDIUM | 4.4 | 0.1% | Aug 20, 2025 | IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authoriz... |
| CVE-2025-8449 | MEDIUM | 4.1 | 0.2% | Aug 20, 2025 | CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticat... |
| CVE-2025-55499 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTi... |
| CVE-2025-54927 | MEDIUM | 4.9 | 0.6% | Aug 20, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-54175 | MEDIUM | 6.1 | 0.2% | Aug 20, 2025 | QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality. An attacker can c... |
| CVE-2025-54174 | MEDIUM | 4.3 | 0.1% | Aug 20, 2025 | QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft spe... |
| CVE-2025-54172 | MEDIUM | 4.8 | 0.2% | Aug 20, 2025 | QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin pri... |
| CVE-2025-4877 | MEDIUM | 4.5 | 0.2% | Aug 20, 2025 | There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer ... |
| CVE-2025-4437 | MEDIUM | 5.7 | 0.2% | Aug 20, 2025 | There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specify... |
| CVE-2025-43750 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-43749 | MEDIUM | 5.3 | 0.2% | Aug 20, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-8102 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-7777 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker... |
| CVE-2025-43742 | MEDIUM | 6.1 | 0.2% | Aug 20, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025... |
| CVE-2025-43741 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025... |
| CVE-2025-57734 | MEDIUM | 6.5 | 0.7% | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files |
| CVE-2025-57732 | MEDIUM | 6.3 | 0.1% | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership |
| CVE-2025-57731 | MEDIUM | 5.4 | 0.3% | Aug 20, 2025 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content |
| CVE-2025-57730 | MEDIUM | 4.6 | 0.4% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature |
| CVE-2025-57728 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files |
| CVE-2025-9229 | MEDIUM | 5.3 | 0.3% | Aug 20, 2025 | Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated att... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now