2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9879 | MEDIUM | 6.4 | 0.2% | Sep 12, 2025 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s... |
| CVE-2025-9877 | MEDIUM | 6.4 | 0.2% | Sep 12, 2025 | The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' sh... |
| CVE-2025-10278 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/tr... |
| CVE-2025-43789 | MEDIUM | 5.3 | 0.2% | Sep 12, 2025 | JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through... |
| CVE-2025-43788 | MEDIUM | 4.3 | 0.2% | Sep 12, 2025 | The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.... |
| CVE-2025-10277 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file... |
| CVE-2025-10276 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown cod... |
| CVE-2025-10269 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.... |
| CVE-2025-9807 | HIGH | 7.5 | 0.3% | Sep 12, 2025 | The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all vers... |
| CVE-2025-58754 | HIGH | 7.5 | 1.1% | Sep 12, 2025 | Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to ver... |
| CVE-2025-55319 | CRITICAL | 9.8 | 0.8% | Sep 12, 2025 | Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network... |
| CVE-2025-10275 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/busine... |
| CVE-2025-10274 | MEDIUM | 6.1 | 0.3% | Sep 12, 2025 | A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the fi... |
| CVE-2025-10273 | MEDIUM | 5.3 | 0.7% | Sep 12, 2025 | A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f... |
| CVE-2025-4974 | — | — | — | Sep 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-10272 | MEDIUM | 6.1 | 0.3% | Sep 11, 2025 | A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. T... |
| CVE-2025-10271 | MEDIUM | 6.1 | 0.3% | Sep 11, 2025 | A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The mani... |
| CVE-2025-36222 | CRITICAL | 9.8 | 0.4% | Sep 11, 2025 | IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.... |
| CVE-2025-10298 | — | — | — | Sep 11, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-10127 | CRITICAL | 9.8 | 0.6% | Sep 11, 2025 | Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerabilit... |
| CVE-2025-9319 | HIGH | 7.5 | 0.2% | Sep 11, 2025 | A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under ce... |
| CVE-2025-9214 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited devi... |
| CVE-2025-9201 | HIGH | 8.5 | 0.2% | Sep 11, 2025 | A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that cou... |
| CVE-2025-8557 | HIGH | 8.8 | 0.2% | Sep 11, 2025 | An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attack... |
| CVE-2025-8061 | HIGH | 7.3 | 0.4% | Sep 11, 2025 | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drive... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now