2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10218 | CRITICAL | 9.8 | 0.3% | Sep 10, 2025 | A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/d... |
| CVE-2025-59052 | HIGH | 7.1 | 0.3% | Sep 10, 2025 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2025-10216 | LOW | 2.6 | 0.2% | Sep 10, 2025 | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout... |
| CVE-2025-54376 | HIGH | 7.5 | 0.7% | Sep 10, 2025 | Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v... |
| CVE-2025-43783 | MEDIUM | 6.1 | 0.2% | Sep 10, 2025 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3... |
| CVE-2025-10211 | MEDIUM | 6.3 | 0.7% | Sep 10, 2025 | A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectCo... |
| CVE-2025-9714 | MEDIUM | 5.5 | 0.1% | Sep 10, 2025 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to caus... |
| CVE-2025-59049 | HIGH | 7.5 | 1.7% | Sep 10, 2025 | Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file servi... |
| CVE-2025-54123 | CRITICAL | 9.8 | 10.5% | Sep 10, 2025 | Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i... |
| CVE-2025-43784 | MEDIUM | 6.5 | 0.2% | Sep 10, 2025 | Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024... |
| CVE-2025-10210 | HIGH | 8.8 | 1.2% | Sep 10, 2025 | A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modu... |
| CVE-2025-10209 | MEDIUM | 5.4 | 0.3% | Sep 10, 2025 | A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the com... |
| CVE-2025-10201 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo... |
| CVE-2025-10200 | HIGH | 8.8 | 0.6% | Sep 10, 2025 | Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti... |
| CVE-2025-8696 | HIGH | 7.5 | 0.4% | Sep 10, 2025 | If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for t... |
| CVE-2025-57392 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone... |
| CVE-2025-55976 | HIGH | 8.4 | 3.0% | Sep 10, 2025 | Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us... |
| CVE-2025-50892 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges f... |
| CVE-2025-57642 | HIGH | 7.2 | 1.5% | Sep 10, 2025 | A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she... |
| CVE-2025-57520 | MEDIUM | 6.1 | 0.3% | Sep 10, 2025 | A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and d... |
| CVE-2025-43785 | MEDIUM | 6.1 | 0.2% | Sep 10, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 ... |
| CVE-2025-8681 | MEDIUM | 5.4 | 0.2% | Sep 10, 2025 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requi... |
| CVE-2025-59045 | HIGH | 7.1 | 0.3% | Sep 10, 2025 | Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion... |
| CVE-2025-59041 | CRITICAL | 9.8 | 0.5% | Sep 10, 2025 | Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema... |
| CVE-2025-59035 | MEDIUM | 5.4 | 0.2% | Sep 10, 2025 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now