2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50579 | MEDIUM | 5.3 | 0.4% | Aug 19, 2025 | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularl... |
| CVE-2025-9140 | HIGH | 8.8 | 0.4% | Aug 19, 2025 | A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this ... |
| CVE-2025-54336 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b... |
| CVE-2025-50567 | CRITICAL | 10 | 0.7% | Aug 19, 2025 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac... |
| CVE-2025-50461 | MEDIUM | 6.5 | 0.5% | Aug 19, 2025 | A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script wh... |
| CVE-2025-4690 | MEDIUM | 4.3 | 0.2% | Aug 19, 2025 | A regular expression used by AngularJS' linky https://docs.angularjs.org/api/ngSanitize/filter/linky filter to detect ... |
| CVE-2025-4046 | HIGH | 8.5 | 0.3% | Aug 19, 2025 | A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges with... |
| CVE-2025-4044 | HIGH | 8.2 | 0.1% | Aug 19, 2025 | Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to ... |
| CVE-2025-43739 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-9139 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the f... |
| CVE-2025-9138 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Perform... |
| CVE-2025-9137 | MEDIUM | 4.8 | 0.3% | Aug 19, 2025 | A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm.... |
| CVE-2025-43740 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0... |
| CVE-2025-9136 | HIGH | 7.8 | 0.2% | Aug 19, 2025 | A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the fil... |
| CVE-2025-9135 | MEDIUM | 5.5 | 0.3% | Aug 19, 2025 | A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 1... |
| CVE-2025-9134 | MEDIUM | 5.5 | 0.2% | Aug 19, 2025 | A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected elemen... |
| CVE-2025-8783 | MEDIUM | 4.4 | 0.3% | Aug 19, 2025 | The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all v... |
| CVE-2025-8567 | MEDIUM | 6.4 | 0.2% | Aug 19, 2025 | The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions... |
| CVE-2025-41689 | HIGH | 7.5 | 0.3% | Aug 19, 2025 | An unauthenticated remote attacker can get access without password protection to the affected device. This enables the u... |
| CVE-2025-41685 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's... |
| CVE-2025-8723 | CRITICAL | 9.8 | 14.0% | Aug 19, 2025 | The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication ... |
| CVE-2025-8622 | MEDIUM | 6.4 | 0.3% | Aug 19, 2025 | The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortc... |
| CVE-2025-7670 | HIGH | 7.5 | 0.5% | Aug 19, 2025 | The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in... |
| CVE-2025-7654 | HIGH | 8.8 | 0.6% | Aug 19, 2025 | Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes ... |
| CVE-2025-8218 | HIGH | 8.8 | 0.3% | Aug 19, 2025 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now