2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57106 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi... |
| CVE-2025-12501 | HIGH | 7.5 | 0.5% | Oct 31, 2025 | Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-... |
| CVE-2025-64386 | HIGH | 7.7 | 0.3% | Oct 31, 2025 | The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of... |
| CVE-2025-33003 | HIGH | 7.8 | 0.1% | Oct 31, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi... |
| CVE-2025-64366 | HIGH | 7.6 | 0.3% | Oct 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu... |
| CVE-2025-64364 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64363 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64360 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64359 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64353 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P... |
| CVE-2025-58149 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the... |
| CVE-2025-58148 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-58147 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-12115 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi... |
| CVE-2025-11843 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun... |
| CVE-2025-62232 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f... |
| CVE-2025-30189 | HIGH | 7.4 | 0.5% | Oct 31, 2025 | When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached ... |
| CVE-2025-30188 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform... |
| CVE-2025-10897 | HIGH | 8.6 | 1.8% | Oct 31, 2025 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi... |
| CVE-2025-7846 | HIGH | 8.8 | 0.6% | Oct 31, 2025 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2025-63675 | HIGH | 8.8 | 0.2% | Oct 31, 2025 | cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt... |
| CVE-2025-54763 | HIGH | 8.6 | 1.3% | Oct 31, 2025 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user... |
| CVE-2025-8849 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api... |
| CVE-2025-6176 | HIGH | 7.5 | 0.5% | Oct 31, 2025 | Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio... |
| CVE-2025-52664 | HIGH | 8.8 | 0.9% | Oct 31, 2025 | SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now