2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10329 | CRITICAL | 9.8 | 0.4% | Sep 12, 2025 | A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/contro... |
| CVE-2025-10328 | CRITICAL | 9.8 | 9.4% | Sep 12, 2025 | A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unkn... |
| CVE-2025-10176 | HIGH | 7.2 | 0.7% | Sep 12, 2025 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici... |
| CVE-2025-45587 | HIGH | 7 | 0.2% | Sep 12, 2025 | A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of... |
| CVE-2025-45586 | HIGH | 7.5 | 0.3% | Sep 12, 2025 | An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a ... |
| CVE-2025-45585 | MEDIUM | 5.4 | 0.2% | Sep 12, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attacke... |
| CVE-2025-45584 | HIGH | 7.5 | 0.4% | Sep 12, 2025 | Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download ... |
| CVE-2025-45583 | CRITICAL | 9.1 | 0.3% | Sep 12, 2025 | Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenti... |
| CVE-2025-10327 | CRITICAL | 9.8 | 10.2% | Sep 12, 2025 | A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown fu... |
| CVE-2025-10326 | CRITICAL | 9.8 | 7.1% | Sep 12, 2025 | A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the fil... |
| CVE-2025-43796 | HIGH | 7.5 | 0.3% | Sep 12, 2025 | Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA... |
| CVE-2025-43795 | MEDIUM | 6.1 | 0.2% | Sep 12, 2025 | Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 ... |
| CVE-2025-10325 | HIGH | 8.8 | 6.8% | Sep 12, 2025 | A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file... |
| CVE-2025-10324 | CRITICAL | 9.8 | 8.1% | Sep 12, 2025 | A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.c... |
| CVE-2025-10323 | CRITICAL | 9.8 | 8.1% | Sep 12, 2025 | A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wiz... |
| CVE-2025-58434 | CRITICAL | 9.8 | 50.1% | Sep 12, 2025 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, t... |
| CVE-2025-4235 | HIGH | 7.2 | 0.2% | Sep 12, 2025 | An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the ... |
| CVE-2025-4234 | LOW | 2.4 | 0.1% | Sep 12, 2025 | A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials ... |
| CVE-2025-10322 | MEDIUM | 5.5 | 0.4% | Sep 12, 2025 | A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sy... |
| CVE-2025-10321 | MEDIUM | 5.5 | 0.5% | Sep 12, 2025 | A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Exec... |
| CVE-2025-56467 | MEDIUM | 6.5 | 0.3% | Sep 12, 2025 | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information w... |
| CVE-2025-52074 | MEDIUM | 6.1 | 0.2% | Sep 12, 2025 | PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in t... |
| CVE-2025-43787 | MEDIUM | 5.4 | 0.2% | Sep 12, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2... |
| CVE-2025-57579 | HIGH | 8 | 0.6% | Sep 12, 2025 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2025-57578 | HIGH | 8 | 0.4% | Sep 12, 2025 | An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now