2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50735 | HIGH | 7.5 | 0.8% | Nov 3, 2025 | Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot ... |
| CVE-2025-63441 | HIGH | 7.3 | 0.2% | Nov 3, 2025 | Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u... |
| CVE-2025-60785 | HIGH | 8.8 | 0.6% | Nov 3, 2025 | A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attac... |
| CVE-2025-60503 | HIGH | 8.7 | 0.3% | Nov 3, 2025 | A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 whe... |
| CVE-2025-36093 | HIGH | 7.4 | 0.2% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content ... |
| CVE-2025-11761 | HIGH | 7.8 | 0.2% | Nov 3, 2025 | A potential security vulnerability has been identified in the HP Client Management Script Library software, which might ... |
| CVE-2025-48397 | HIGH | 7.1 | 0.2% | Nov 3, 2025 | The privileged user could log in without sufficient credentials after enabling an application protocol. This security is... |
| CVE-2025-48396 | HIGH | 8.3 | 0.3% | Nov 3, 2025 | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This sec... |
| CVE-2025-12503 | HIGH | 7.1 | 0.3% | Nov 3, 2025 | EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote a... |
| CVE-2025-12615 | HIGH | 8.1 | 0.3% | Nov 3, 2025 | A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of... |
| CVE-2025-12610 | HIGH | 7.2 | 0.3% | Nov 3, 2025 | A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/v... |
| CVE-2025-12609 | HIGH | 8.8 | 0.3% | Nov 3, 2025 | A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality o... |
| CVE-2025-12594 | HIGH | 7.2 | 0.4% | Nov 2, 2025 | A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown... |
| CVE-2025-12593 | HIGH | 7.2 | 0.4% | Nov 2, 2025 | A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u... |
| CVE-2025-12601 | HIGH | 7.5 | 0.3% | Nov 1, 2025 | Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-36367 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz... |
| CVE-2025-6990 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via ... |
| CVE-2025-6574 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-12171 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
| CVE-2025-11755 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar... |
| CVE-2025-10487 | HIGH | 7.3 | 0.4% | Nov 1, 2025 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up t... |
| CVE-2025-5949 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-11995 | HIGH | 7.2 | 0.2% | Nov 1, 2025 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al... |
| CVE-2025-11920 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14... |
| CVE-2025-63561 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Serv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now