2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57763 | MEDIUM | 6.1 | 0.2% | Aug 21, 2025 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Reflected Cross-Site Scripting (XSS) vuln... |
| CVE-2025-57762 | MEDIUM | 6.1 | 0.2% | Aug 21, 2025 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Stored Cross-Site Scripting (XSS) vulnera... |
| CVE-2025-57761 | HIGH | 8.8 | 0.4% | Aug 21, 2025 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html... |
| CVE-2025-57755 | HIGH | 8.1 | 0.3% | Aug 21, 2025 | claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due t... |
| CVE-2025-57754 | CRITICAL | 9.8 | 0.3% | Aug 21, 2025 | eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is ex... |
| CVE-2025-55522 | MEDIUM | 6.5 | 0.4% | Aug 21, 2025 | Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execu... |
| CVE-2025-55521 | MEDIUM | 6.5 | 0.4% | Aug 21, 2025 | An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial o... |
| CVE-2025-43756 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | <!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerabi... |
| CVE-2025-43755 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, ... |
| CVE-2025-9308 | MEDIUM | 5.5 | 0.2% | Aug 21, 2025 | A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/... |
| CVE-2025-9307 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/... |
| CVE-2025-9306 | MEDIUM | 5.4 | 0.3% | Aug 21, 2025 | A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown... |
| CVE-2025-9162 | MEDIUM | 4.9 | 0.5% | Aug 21, 2025 | A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes pla... |
| CVE-2025-57753 | MEDIUM | 6 | 0.4% | Aug 21, 2025 | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible... |
| CVE-2025-55744 | MEDIUM | 4.3 | 0.1% | Aug 21, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some ... |
| CVE-2025-55743 | HIGH | 8.8 | 0.4% | Aug 21, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the i... |
| CVE-2025-55742 | MEDIUM | 4.8 | 0.3% | Aug 21, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPi... |
| CVE-2025-55420 | HIGH | 8.8 | 0.5% | Aug 21, 2025 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is ... |
| CVE-2025-52395 | CRITICAL | 9.8 | 0.5% | Aug 21, 2025 | An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password ... |
| CVE-2025-9305 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is ... |
| CVE-2025-9304 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of t... |
| CVE-2025-9303 | CRITICAL | 9.8 | 0.8% | Aug 21, 2025 | A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParental... |
| CVE-2025-55383 | HIGH | 8.6 | 0.3% | Aug 21, 2025 | Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files ... |
| CVE-2025-55371 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers... |
| CVE-2025-55297 | HIGH | 8.8 | 0.3% | Aug 21, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulner... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now