2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57887MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonste...
CVE-2025-57886MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Dig...
CVE-2025-57885MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Cross Site Reque...
CVE-2025-57884MEDIUM4.3Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting ...
CVE-2025-9340NONE0Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules...
CVE-2025-9341MEDIUM5.9Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ...
CVE-2025-8678MEDIUM5.9The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via...
CVE-2025-57699HIGH8.4Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted ...
CVE-2025-8281HIGH7.1The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2025-41452MEDIUM6.8Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Ser...
CVE-2025-41451HIGH8.7Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfo...
CVE-2025-43752MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43753MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2...
CVE-2025-51606HIGH8.8hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with ac...
CVE-2025-43747MEDIUM6.5A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure...
CVE-2025-55231HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an...
CVE-2025-55230HIGH7.8Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locall...
CVE-2025-55229MEDIUM5.3Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoo...
CVE-2025-55107MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11...
CVE-2025-55106MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t...
CVE-2025-55105MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t...
CVE-2025-55104MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenti...
CVE-2025-55103MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t...
CVE-2025-54460HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publicatio...
CVE-2025-53795CRITICAL9.8Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now