2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47870 | MEDIUM | 4.3 | 0.2% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team in... |
| CVE-2025-47700 | LOW | 3.5 | 0.2% | Aug 21, 2025 | Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows... |
| CVE-2025-36530 | MEDIUM | 4.9 | 0.5% | Aug 21, 2025 | Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate fi... |
| CVE-2025-8607 | MEDIUM | 6.4 | 0.2% | Aug 21, 2025 | The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-8592 | HIGH | 8.1 | 0.2% | Aug 21, 2025 | The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2.... |
| CVE-2025-7390 | CRITICAL | 9.1 | 0.2% | Aug 21, 2025 | A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is conf... |
| CVE-2025-7221 | MEDIUM | 4.3 | 0.2% | Aug 21, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2025-53505 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabil... |
| CVE-2025-53504 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vuln... |
| CVE-2025-57832 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57831 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57830 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57829 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57828 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57827 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57826 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57825 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-57824 | — | — | — | Aug 21, 2025 | Rejected reason: Not used |
| CVE-2025-48355 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource ... |
| CVE-2025-48978 | HIGH | 7.5 | 0.7% | Aug 21, 2025 | An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a mal... |
| CVE-2025-43300 | CRITICAL | 10 | 20.0% | Aug 21, 2025 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1... |
| CVE-2025-27217 | CRITICAL | 9.1 | 0.4% | Aug 21, 2025 | A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to mak... |
| CVE-2025-27216 | HIGH | 8.8 | 0.3% | Aug 21, 2025 | Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with cert... |
| CVE-2025-27215 | HIGH | 8.1 | 0.2% | Aug 21, 2025 | An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast ... |
| CVE-2025-27214 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now