2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57887 | MEDIUM | 6.5 | 0.2% | Aug 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonste... |
| CVE-2025-57886 | MEDIUM | 5.4 | 0.2% | Aug 22, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Dig... |
| CVE-2025-57885 | MEDIUM | 4.3 | 0.1% | Aug 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Cross Site Reque... |
| CVE-2025-57884 | MEDIUM | 4.3 | 0.2% | Aug 22, 2025 | Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting ... |
| CVE-2025-9340 | NONE | 0 | 0.2% | Aug 22, 2025 | Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules... |
| CVE-2025-9341 | MEDIUM | 5.9 | 0.1% | Aug 22, 2025 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ... |
| CVE-2025-8678 | MEDIUM | 5.9 | 0.3% | Aug 22, 2025 | The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via... |
| CVE-2025-57699 | HIGH | 8.4 | 0.2% | Aug 22, 2025 | Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted ... |
| CVE-2025-8281 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2025-41452 | MEDIUM | 6.8 | 0.2% | Aug 22, 2025 | Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Ser... |
| CVE-2025-41451 | HIGH | 8.7 | 0.9% | Aug 22, 2025 | Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfo... |
| CVE-2025-43752 | MEDIUM | 6.5 | 0.3% | Aug 22, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-43753 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2... |
| CVE-2025-51606 | HIGH | 8.8 | 0.3% | Aug 21, 2025 | hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with ac... |
| CVE-2025-43747 | MEDIUM | 6.5 | 0.2% | Aug 21, 2025 | A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure... |
| CVE-2025-55231 | HIGH | 7.5 | 0.4% | Aug 21, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an... |
| CVE-2025-55230 | HIGH | 7.8 | 0.3% | Aug 21, 2025 | Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locall... |
| CVE-2025-55229 | MEDIUM | 5.3 | 0.4% | Aug 21, 2025 | Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoo... |
| CVE-2025-55107 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11... |
| CVE-2025-55106 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t... |
| CVE-2025-55105 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t... |
| CVE-2025-55104 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenti... |
| CVE-2025-55103 | MEDIUM | 4.8 | 0.2% | Aug 21, 2025 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t... |
| CVE-2025-54460 | HIGH | 7.1 | 0.3% | Aug 21, 2025 | The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publicatio... |
| CVE-2025-53795 | CRITICAL | 9.8 | 0.6% | Aug 21, 2025 | Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now