2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50579MEDIUM5.3A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularl...
CVE-2025-9140HIGH8.8A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this ...
CVE-2025-54336CRITICAL9.8In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b...
CVE-2025-50567CRITICAL10Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac...
CVE-2025-50461MEDIUM6.5A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script wh...
CVE-2025-4690MEDIUM4.3A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect ...
CVE-2025-4046HIGH8.5A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges with...
CVE-2025-4044HIGH8.2Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to ...
CVE-2025-43739MEDIUM4.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-9139MEDIUM6.5A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the f...
CVE-2025-9138MEDIUM5.4A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Perform...
CVE-2025-9137MEDIUM4.8A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm....
CVE-2025-43740MEDIUM5.4A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0...
CVE-2025-9136HIGH7.8A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the fil...
CVE-2025-9135MEDIUM5.5A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 1...
CVE-2025-9134MEDIUM5.5A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected elemen...
CVE-2025-8783MEDIUM4.4The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all v...
CVE-2025-8567MEDIUM6.4The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions...
CVE-2025-41689HIGH7.5An unauthenticated remote attacker can get access without password protection to the affected device. This enables the u...
CVE-2025-41685MEDIUM6.5A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's...
CVE-2025-8723CRITICAL9.8The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication ...
CVE-2025-8622MEDIUM6.4The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortc...
CVE-2025-7670HIGH7.5The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in...
CVE-2025-7654HIGH8.8Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes ...
CVE-2025-8218HIGH8.8The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now