2025 CVE Vulnerabilities

45,244 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10218CRITICAL9.8A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/d...
CVE-2025-59052HIGH7.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2025-10216LOW2.6A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout...
CVE-2025-54376HIGH7.5Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v...
CVE-2025-43783MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3...
CVE-2025-10211MEDIUM6.3A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectCo...
CVE-2025-9714MEDIUM5.5Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to caus...
CVE-2025-59049HIGH7.5Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file servi...
CVE-2025-54123CRITICAL9.8Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i...
CVE-2025-43784MEDIUM6.5Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024...
CVE-2025-10210HIGH8.8A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modu...
CVE-2025-10209MEDIUM5.4A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the com...
CVE-2025-10201HIGH8.8Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo...
CVE-2025-10200HIGH8.8Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti...
CVE-2025-8696HIGH7.5If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for t...
CVE-2025-57392HIGH7.8BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone...
CVE-2025-55976HIGH8.4Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us...
CVE-2025-50892HIGH7.8The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges f...
CVE-2025-57642HIGH7.2A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she...
CVE-2025-57520MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and d...
CVE-2025-43785MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 ...
CVE-2025-8681MEDIUM5.4Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requi...
CVE-2025-59045HIGH7.1Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion...
CVE-2025-59041CRITICAL9.8Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema...
CVE-2025-59035MEDIUM5.4Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now