2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9879MEDIUM6.4The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s...
CVE-2025-9877MEDIUM6.4The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' sh...
CVE-2025-10278HIGH8.8A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/tr...
CVE-2025-43789MEDIUM5.3JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through...
CVE-2025-43788MEDIUM4.3The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7....
CVE-2025-10277HIGH8.8A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file...
CVE-2025-10276HIGH8.8A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown cod...
CVE-2025-10269HIGH7.5The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1....
CVE-2025-9807HIGH7.5The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all vers...
CVE-2025-58754HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to ver...
CVE-2025-55319CRITICAL9.8Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network...
CVE-2025-10275HIGH8.8A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/busine...
CVE-2025-10274MEDIUM6.1A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the fi...
CVE-2025-10273MEDIUM5.3A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f...
CVE-2025-4974Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-10272MEDIUM6.1A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. T...
CVE-2025-10271MEDIUM6.1A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The mani...
CVE-2025-36222CRITICAL9.8IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10....
CVE-2025-10298Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-10127CRITICAL9.8Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerabilit...
CVE-2025-9319HIGH7.5A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under ce...
CVE-2025-9214MEDIUM5.4A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited devi...
CVE-2025-9201HIGH8.5A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that cou...
CVE-2025-8557HIGH8.8An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attack...
CVE-2025-8061HIGH7.3A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drive...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now