2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56761 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar f... |
| CVE-2025-56760 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint co... |
| CVE-2025-56689 | MEDIUM | 4.6 | 1.3% | Sep 3, 2025 | One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/... |
| CVE-2025-9920 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of... |
| CVE-2025-9919 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of... |
| CVE-2025-56498 | MEDIUM | 5.3 | 1.7% | Sep 3, 2025 | An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interf... |
| CVE-2025-56435 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file... |
| CVE-2025-55944 | MEDIUM | 6.1 | 0.3% | Sep 3, 2025 | Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a n... |
| CVE-2025-55852 | HIGH | 7.5 | 0.4% | Sep 3, 2025 | Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or s... |
| CVE-2025-48876 | — | — | — | Sep 3, 2025 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2025-0280 | HIGH | 7.5 | 0.1% | Sep 3, 2025 | A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access. |
| CVE-2025-9824 | MEDIUM | 5.9 | 0.3% | Sep 3, 2025 | ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used ... |
| CVE-2025-9823 | MEDIUM | 4.8 | 0.3% | Sep 3, 2025 | SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of a... |
| CVE-2025-58644 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes... |
| CVE-2025-58643 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-q... |
| CVE-2025-58642 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight... |
| CVE-2025-58641 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Server-Side Request Forgery (SSRF) vulnerability in kamleshyadav Exit Intent Popup exitintentpopup allows Server Side Re... |
| CVE-2025-58640 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Docum... |
| CVE-2025-58639 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in Ali Khallad Contact Form By Mega Forms mega-forms allows Exploiting Incorrectly C... |
| CVE-2025-58637 | HIGH | 7.5 | 0.4% | Sep 3, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58635 | MEDIUM | 5.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configure... |
| CVE-2025-58634 | MEDIUM | 5.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly... |
| CVE-2025-58633 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking ... |
| CVE-2025-58632 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dadevarzan Dadevar... |
| CVE-2025-58631 | MEDIUM | 5.9 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZEEN101 IssueM iss... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now