2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43800 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q... |
| CVE-2025-10473 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the f... |
| CVE-2025-10472 | HIGH | 7.5 | 0.8% | Sep 15, 2025 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download... |
| CVE-2025-55777 | — | — | — | Sep 15, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2025-52344 | MEDIUM | 6.1 | 0.3% | Sep 15, 2025 | Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject ... |
| CVE-2025-43791 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0... |
| CVE-2025-59328 | MEDIUM | 6.5 | 0.6% | Sep 15, 2025 | A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the ins... |
| CVE-2025-59155 | MEDIUM | 6.9 | 0.3% | Sep 15, 2025 | hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4... |
| CVE-2025-58748 | CRITICAL | 9.8 | 0.8% | Sep 15, 2025 | Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data sou... |
| CVE-2025-58177 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scriptin... |
| CVE-2025-58172 | MEDIUM | 5.3 | 0.4% | Sep 15, 2025 | drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vu... |
| CVE-2025-57176 | MEDIUM | 6.5 | 0.4% | Sep 15, 2025 | On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip... |
| CVE-2025-57174 | CRITICAL | 9.8 | 1.2% | Sep 15, 2025 | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p... |
| CVE-2025-57104 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx. |
| CVE-2025-49089 | MEDIUM | 6.3 | 0.3% | Sep 15, 2025 | wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd... |
| CVE-2025-43792 | MEDIUM | 5.3 | 0.3% | Sep 15, 2025 | Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 202... |
| CVE-2025-10471 | HIGH | 8.8 | 0.3% | Sep 15, 2025 | A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaCon... |
| CVE-2025-10203 | HIGH | 8.5 | 0.2% | Sep 15, 2025 | Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar... |
| CVE-2025-59397 | MEDIUM | 5 | 0.4% | Sep 15, 2025 | Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection. |
| CVE-2025-58046 | CRITICAL | 9.8 | 1.3% | Sep 15, 2025 | Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala... |
| CVE-2025-58045 | CRITICAL | 9.8 | 0.6% | Sep 15, 2025 | Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch intr... |
| CVE-2025-57248 | HIGH | 7.3 | 0.2% | Sep 15, 2025 | A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu fil... |
| CVE-2025-56252 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted... |
| CVE-2025-52048 | MEDIUM | 6.5 | 0.2% | Sep 15, 2025 | In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py... |
| CVE-2025-43793 | HIGH | 7.5 | 0.4% | Sep 15, 2025 | Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now