2025 CVE Vulnerabilities
45,246 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55727 | CRITICAL | 9.8 | 1.0% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55052 | MEDIUM | 4.3 | 0.3% | Sep 9, 2025 | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2025-55051 | CRITICAL | 10 | 0.3% | Sep 9, 2025 | CWE-1392: Use of Default Credentials |
| CVE-2025-55050 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | CWE-1242: Inclusion of Undocumented Features |
| CVE-2025-55049 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | Use of Default Cryptographic Key (CWE-1394) |
| CVE-2025-55048 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | Multiple CWE-78 |
| CVE-2025-55047 | HIGH | 8.4 | 0.1% | Sep 9, 2025 | CWE-798 Use of Hard-coded Credentials |
| CVE-2025-54256 | HIGH | 8.6 | 0.2% | Sep 9, 2025 | Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that cou... |
| CVE-2025-54242 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbit... |
| CVE-2025-43781 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q... |
| CVE-2025-43775 | MEDIUM | 5.4 | 0.2% | Sep 9, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 thr... |
| CVE-2025-29089 | HIGH | 7.5 | 0.5% | Sep 9, 2025 | An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information |
| CVE-2025-10164 | HIGH | 7.3 | 0.4% | Sep 9, 2025 | A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the fi... |
| CVE-2025-9269 | MEDIUM | 6.9 | 0.3% | Sep 9, 2025 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark dev... |
| CVE-2025-57665 | MEDIUM | 6.4 | 0.2% | Sep 9, 2025 | Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, cr... |
| CVE-2025-57086 | HIGH | 7.5 | 0.4% | Sep 9, 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNo... |
| CVE-2025-57085 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function.... |
| CVE-2025-57078 | HIGH | 7.5 | 0.4% | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the ... |
| CVE-2025-10199 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver... |
| CVE-2025-10198 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers ... |
| CVE-2025-5500 | MEDIUM | 5.3 | 0.1% | Sep 9, 2025 | A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file Andr... |
| CVE-2025-5005 | HIGH | 7.3 | 0.4% | Sep 9, 2025 | A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unk... |
| CVE-2025-59008 | HIGH | 7.6 | 0.3% | Sep 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Co... |
| CVE-2025-59005 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-58997 | CRITICAL | 9.6 | 0.2% | Sep 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now