2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64353 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P... |
| CVE-2025-58149 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the... |
| CVE-2025-58148 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-58147 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-12115 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi... |
| CVE-2025-11843 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun... |
| CVE-2025-62232 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f... |
| CVE-2025-30189 | HIGH | 7.4 | 0.5% | Oct 31, 2025 | When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached ... |
| CVE-2025-30188 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform... |
| CVE-2025-10897 | HIGH | 8.6 | 1.8% | Oct 31, 2025 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi... |
| CVE-2025-7846 | HIGH | 8.8 | 0.6% | Oct 31, 2025 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2025-63675 | HIGH | 8.8 | 0.2% | Oct 31, 2025 | cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt... |
| CVE-2025-54763 | HIGH | 8.6 | 1.3% | Oct 31, 2025 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user... |
| CVE-2025-8849 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api... |
| CVE-2025-6176 | HIGH | 7.5 | 0.5% | Oct 31, 2025 | Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio... |
| CVE-2025-52664 | HIGH | 8.8 | 0.9% | Oct 31, 2025 | SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo... |
| CVE-2025-52663 | HIGH | 7.3 | 0.2% | Oct 31, 2025 | A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention... |
| CVE-2025-48984 | HIGH | 8.8 | 1.0% | Oct 31, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| CVE-2025-48982 | HIGH | 7.8 | 0.2% | Oct 31, 2025 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator ... |
| CVE-2025-34298 | HIGH | 8.8 | 0.6% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change ... |
| CVE-2025-34287 | HIGH | 7.8 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical... |
| CVE-2025-34286 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C... |
| CVE-2025-34284 | HIGH | 8.8 | 4.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio... |
| CVE-2025-34280 | HIGH | 7.2 | 1.3% | Oct 30, 2025 | Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function... |
| CVE-2025-34134 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now