2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54234 | LOW | 2.7 | 0.7% | Aug 18, 2025 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabil... |
| CVE-2025-3639 | LOW | 2 | 0.5% | Aug 18, 2025 | Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.... |
| CVE-2025-54421 | MEDIUM | 5.4 | 0.4% | Aug 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab... |
| CVE-2025-54118 | MEDIUM | 5.3 | 0.4% | Aug 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in... |
| CVE-2025-54117 | MEDIUM | 5.4 | 0.4% | Aug 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab... |
| CVE-2025-4962 | HIGH | 7.7 | 0.2% | Aug 18, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna... |
| CVE-2025-43732 | LOW | 2.7 | 0.2% | Aug 18, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.... |
| CVE-2025-36120 | HIGH | 8.8 | 0.3% | Aug 18, 2025 | IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s... |
| CVE-2025-33100 | HIGH | 7.5 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, whi... |
| CVE-2025-33090 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr... |
| CVE-2025-27909 | CRITICAL | 9.8 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carr... |
| CVE-2025-1759 | HIGH | 7.5 | 0.3% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me... |
| CVE-2025-43733 | MEDIUM | 5.4 | 0.2% | Aug 18, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through ... |
| CVE-2025-47206 | HIGH | 8.1 | 0.4% | Aug 18, 2025 | An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accou... |
| CVE-2025-41242 | MEDIUM | 5.9 | 1.9% | Aug 18, 2025 | Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant... |
| CVE-2025-5296 | HIGH | 7.3 | 0.2% | Aug 18, 2025 | CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary ... |
| CVE-2025-6625 | HIGH | 8.7 | 0.5% | Aug 18, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP co... |
| CVE-2025-57703 | MEDIUM | 6.1 | 0.1% | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting |
| CVE-2025-57702 | MEDIUM | 6.1 | 0.1% | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting |
| CVE-2025-57701 | MEDIUM | 6.1 | 0.1% | Aug 18, 2025 | DIAEnergie - Reflected Cross-site Scripting |
| CVE-2025-57700 | MEDIUM | 6.1 | 0.2% | Aug 18, 2025 | DIAEnergie - Stored Cross-site Scripting |
| CVE-2025-9109 | LOW | 3.7 | 0.4% | Aug 18, 2025 | A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown fun... |
| CVE-2025-9108 | MEDIUM | 4.3 | 0.3% | Aug 18, 2025 | Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ... |
| CVE-2025-9107 | MEDIUM | 6.1 | 0.4% | Aug 18, 2025 | A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/... |
| CVE-2025-9106 | MEDIUM | 5.4 | 0.3% | Aug 18, 2025 | A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-en... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now