2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59725 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-59724 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-59723 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-59722 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-59721 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-59720 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-10652 | MEDIUM | 6.5 | 0.3% | Sep 20, 2025 | The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-net... |
| CVE-2025-43808 | MEDIUM | 5.3 | 0.3% | Sep 19, 2025 | The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1... |
| CVE-2025-9081 | MEDIUM | 6.5 | 0.3% | Sep 19, 2025 | Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authe... |
| CVE-2025-9079 | HIGH | 7.2 | 0.6% | Sep 19, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ... |
| CVE-2025-59689 | MEDIUM | 6.1 | 1.9% | Sep 19, 2025 | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a ... |
| CVE-2025-59431 | CRITICAL | 9.8 | 0.4% | Sep 19, 2025 | MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive Property... |
| CVE-2025-57396 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework ... |
| CVE-2025-56762 | MEDIUM | 6.1 | 0.3% | Sep 19, 2025 | Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php. |
| CVE-2025-54815 | HIGH | 8.8 | 0.6% | Sep 19, 2025 | Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via craft... |
| CVE-2025-54761 | HIGH | 8 | 0.3% | Sep 19, 2025 | An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. |
| CVE-2025-52159 | HIGH | 8.8 | 0.4% | Sep 19, 2025 | Hardcoded credentials in default configuration of PPress 0.0.9. |
| CVE-2025-43809 | MEDIUM | 4.3 | 0.2% | Sep 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 throug... |
| CVE-2025-10568 | CRITICAL | 9.8 | 0.3% | Sep 19, 2025 | HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to addr... |
| CVE-2025-43803 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.... |
| CVE-2025-34206 | CRITICAL | 9.8 | 0.5% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configu... |
| CVE-2025-34205 | CRITICAL | 9.8 | 1.3% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192... |
| CVE-2025-34204 | CRITICAL | 9.8 | 0.6% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple ... |
| CVE-2025-34203 | CRITICAL | 9.8 | 0.8% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior t... |
| CVE-2025-34202 | HIGH | 8.8 | 0.9% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now