2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55030 | MEDIUM | 6.1 | 0.1% | Aug 19, 2025 | Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont... |
| CVE-2025-55028 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all... |
| CVE-2025-54144 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra... |
| CVE-2025-9157 | MEDIUM | 5.3 | 0.1% | Aug 19, 2025 | A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack... |
| CVE-2025-55740 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engine... |
| CVE-2025-55737 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ow... |
| CVE-2025-52337 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5... |
| CVE-2025-50926 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2025-43744 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2... |
| CVE-2025-43743 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-2988 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 ... |
| CVE-2025-55736 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving... |
| CVE-2025-55735 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte... |
| CVE-2025-55734 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when vis... |
| CVE-2025-55303 | MEDIUM | 6.1 | 0.6% | Aug 19, 2025 | Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimiza... |
| CVE-2025-52338 | MEDIUM | 5.3 | 0.5% | Aug 19, 2025 | An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows... |
| CVE-2025-43745 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 t... |
| CVE-2025-43737 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through ... |
| CVE-2025-33008 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vu... |
| CVE-2025-31988 | MEDIUM | 4.8 | 0.2% | Aug 19, 2025 | HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access. |
| CVE-2025-9151 | MEDIUM | 6.3 | 0.3% | Aug 19, 2025 | A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct... |
| CVE-2025-55295 | MEDIUM | 6.5 | 0.5% | Aug 19, 2025 | qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e... |
| CVE-2025-9148 | MEDIUM | 6.3 | 0.3% | Aug 19, 2025 | A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/se... |
| CVE-2025-9147 | MEDIUM | 6.1 | 0.3% | Aug 19, 2025 | A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted el... |
| CVE-2025-54881 | MEDIUM | 5.3 | 0.7% | Aug 19, 2025 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now