2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9818 | MEDIUM | 6.7 | 0.1% | Sep 17, 2025 | A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided ... |
| CVE-2025-59518 | HIGH | 8 | 1.2% | Sep 17, 2025 | In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It ... |
| CVE-2025-59307 | HIGH | 8.4 | 0.2% | Sep 17, 2025 | RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri... |
| CVE-2025-58116 | HIGH | 8.6 | 1.1% | Sep 17, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and... |
| CVE-2025-55075 | MEDIUM | 6.9 | 0.3% | Sep 17, 2025 | Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled ... |
| CVE-2025-10589 | HIGH | 8.8 | 1.0% | Sep 17, 2025 | The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenti... |
| CVE-2025-10584 | MEDIUM | 5.4 | 0.3% | Sep 17, 2025 | A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/... |
| CVE-2025-10188 | MEDIUM | 5.4 | 0.1% | Sep 17, 2025 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio... |
| CVE-2025-10125 | MEDIUM | 6.4 | 0.3% | Sep 17, 2025 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shor... |
| CVE-2025-9891 | MEDIUM | 4.3 | 0.2% | Sep 17, 2025 | The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9851 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar... |
| CVE-2025-9629 | MEDIUM | 4.3 | 0.2% | Sep 17, 2025 | The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5... |
| CVE-2025-8394 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_producti... |
| CVE-2025-8153 | MEDIUM | 5.1 | 0.3% | Sep 17, 2025 | Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8... |
| CVE-2025-10166 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter'... |
| CVE-2025-10143 | HIGH | 7.5 | 0.6% | Sep 17, 2025 | The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0... |
| CVE-2025-10050 | MEDIUM | 6.6 | 0.8% | Sep 17, 2025 | The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t... |
| CVE-2025-43804 | MEDIUM | 6.1 | 0.2% | Sep 16, 2025 | Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP ... |
| CVE-2025-37131 | MEDIUM | 4.9 | 0.3% | Sep 16, 2025 | A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to acc... |
| CVE-2025-37130 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitr... |
| CVE-2025-37129 | MEDIUM | 6.7 | 0.2% | Sep 16, 2025 | A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi... |
| CVE-2025-37128 | MEDIUM | 6.8 | 0.3% | Sep 16, 2025 | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote a... |
| CVE-2025-37127 | HIGH | 7.2 | 0.1% | Sep 16, 2025 | A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authe... |
| CVE-2025-37126 | HIGH | 7.2 | 0.6% | Sep 16, 2025 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote... |
| CVE-2025-37125 | HIGH | 7.5 | 0.3% | Sep 16, 2025 | A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation coul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now