2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51510 | MEDIUM | 4.9 | 0.5% | Aug 19, 2025 | MoonShine was discovered to contain a SQL injection vulnerability under the Blog -> Categories page when using the moons... |
| CVE-2025-51489 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upl... |
| CVE-2025-51488 | MEDIUM | 4.9 | 0.5% | Aug 19, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to sto... |
| CVE-2025-51487 | MEDIUM | 4.5 | 0.4% | Aug 19, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary Ja... |
| CVE-2025-50897 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical ... |
| CVE-2025-50579 | MEDIUM | 5.3 | 0.4% | Aug 19, 2025 | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularl... |
| CVE-2025-50461 | MEDIUM | 6.5 | 0.5% | Aug 19, 2025 | A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script wh... |
| CVE-2025-4690 | MEDIUM | 4.3 | 0.2% | Aug 19, 2025 | A regular expression used by AngularJS' linky https://docs.angularjs.org/api/ngSanitize/filter/linky filter to detect ... |
| CVE-2025-43739 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-9139 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the f... |
| CVE-2025-9138 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Perform... |
| CVE-2025-9137 | MEDIUM | 4.8 | 0.3% | Aug 19, 2025 | A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm.... |
| CVE-2025-43740 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0... |
| CVE-2025-9135 | MEDIUM | 5.5 | 0.3% | Aug 19, 2025 | A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 1... |
| CVE-2025-9134 | MEDIUM | 5.5 | 0.2% | Aug 19, 2025 | A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected elemen... |
| CVE-2025-8783 | MEDIUM | 4.4 | 0.3% | Aug 19, 2025 | The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all v... |
| CVE-2025-8567 | MEDIUM | 6.4 | 0.2% | Aug 19, 2025 | The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions... |
| CVE-2025-41685 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's... |
| CVE-2025-8622 | MEDIUM | 6.4 | 0.3% | Aug 19, 2025 | The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortc... |
| CVE-2025-8357 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads dir... |
| CVE-2025-5417 | MEDIUM | 6.1 | 0.2% | Aug 19, 2025 | An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image.... |
| CVE-2025-7496 | MEDIUM | 6.4 | 0.2% | Aug 19, 2025 | The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements... |
| CVE-2025-54862 | MEDIUM | 5.4 | 0.2% | Aug 18, 2025 | Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes... |
| CVE-2025-54759 | MEDIUM | 6.1 | 0.2% | Aug 18, 2025 | Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirectin... |
| CVE-2025-55590 | MEDIUM | 6.5 | 0.8% | Aug 18, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bup... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now