2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55032 | MEDIUM | 6.1 | 0.1% | Aug 19, 2025 | Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the conten... |
| CVE-2025-55031 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att... |
| CVE-2025-55030 | MEDIUM | 6.1 | 0.1% | Aug 19, 2025 | Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont... |
| CVE-2025-55029 | HIGH | 7.5 | 0.3% | Aug 19, 2025 | Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. T... |
| CVE-2025-55028 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all... |
| CVE-2025-54145 | CRITICAL | 9.1 | 0.4% | Aug 19, 2025 | The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev... |
| CVE-2025-54144 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra... |
| CVE-2025-54143 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio... |
| CVE-2025-9165 | LOW | 2.5 | 0.2% | Aug 19, 2025 | A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCC... |
| CVE-2025-9157 | MEDIUM | 5.3 | 0.1% | Aug 19, 2025 | A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack... |
| CVE-2025-9156 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of t... |
| CVE-2025-9155 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown func... |
| CVE-2025-55740 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engine... |
| CVE-2025-55737 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ow... |
| CVE-2025-52337 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5... |
| CVE-2025-51543 | CRITICAL | 9.8 | 0.3% | Aug 19, 2025 | An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini... |
| CVE-2025-50926 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2025-43744 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2... |
| CVE-2025-43743 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-2988 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 ... |
| CVE-2025-9154 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown proc... |
| CVE-2025-9153 | HIGH | 8.8 | 0.4% | Aug 19, 2025 | A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects un... |
| CVE-2025-55736 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving... |
| CVE-2025-55735 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte... |
| CVE-2025-55734 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when vis... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now