2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12615 | HIGH | 8.1 | 0.3% | Nov 3, 2025 | A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of... |
| CVE-2025-12610 | HIGH | 7.2 | 0.3% | Nov 3, 2025 | A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/v... |
| CVE-2025-12609 | HIGH | 8.8 | 0.3% | Nov 3, 2025 | A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality o... |
| CVE-2025-12594 | HIGH | 7.2 | 0.4% | Nov 2, 2025 | A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown... |
| CVE-2025-12593 | HIGH | 7.2 | 0.4% | Nov 2, 2025 | A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u... |
| CVE-2025-12601 | HIGH | 7.5 | 0.3% | Nov 1, 2025 | Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-36367 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz... |
| CVE-2025-6990 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via ... |
| CVE-2025-6574 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-12171 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
| CVE-2025-11755 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar... |
| CVE-2025-10487 | HIGH | 7.3 | 0.4% | Nov 1, 2025 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up t... |
| CVE-2025-5949 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-11995 | HIGH | 7.2 | 0.2% | Nov 1, 2025 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al... |
| CVE-2025-11920 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14... |
| CVE-2025-63561 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Serv... |
| CVE-2025-10693 | HIGH | 7.6 | 0.3% | Oct 31, 2025 | When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-... |
| CVE-2025-64349 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, ... |
| CVE-2025-64348 | HIGH | 7.1 | 0.3% | Oct 31, 2025 | ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the ... |
| CVE-2025-63458 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wi... |
| CVE-2025-63454 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentContro... |
| CVE-2025-62618 | HIGH | 8.6 | 0.3% | Oct 31, 2025 | ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u... |
| CVE-2025-12547 | HIGH | 8.1 | 0.8% | Oct 31, 2025 | A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t... |
| CVE-2025-63459 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42... |
| CVE-2025-63465 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42288... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now