2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43800MEDIUM6.1Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q...
CVE-2025-10473CRITICAL9.8A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the f...
CVE-2025-10472HIGH7.5A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download...
CVE-2025-55777Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2025-52344MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject ...
CVE-2025-43791MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0...
CVE-2025-59328MEDIUM6.5A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the ins...
CVE-2025-59155MEDIUM6.9hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4...
CVE-2025-58748CRITICAL9.8Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data sou...
CVE-2025-58177MEDIUM5.4n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scriptin...
CVE-2025-58172MEDIUM5.3drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vu...
CVE-2025-57176MEDIUM6.5On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip...
CVE-2025-57174CRITICAL9.8An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p...
CVE-2025-57104MEDIUM5.4Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx.
CVE-2025-49089MEDIUM6.3wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd...
CVE-2025-43792MEDIUM5.3Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 202...
CVE-2025-10471HIGH8.8A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaCon...
CVE-2025-10203HIGH8.5Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar...
CVE-2025-59397MEDIUM5Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
CVE-2025-58046CRITICAL9.8Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala...
CVE-2025-58045CRITICAL9.8Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch intr...
CVE-2025-57248HIGH7.3A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu fil...
CVE-2025-56252MEDIUM6.1Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted...
CVE-2025-52048MEDIUM6.5In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py...
CVE-2025-43793HIGH7.5Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now