2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12221 | HIGH | 8.8 | 0.2% | Oct 25, 2025 | Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-9322 | HIGH | 7.5 | 0.3% | Oct 25, 2025 | The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is... |
| CVE-2025-8416 | HIGH | 7.5 | 0.4% | Oct 25, 2025 | The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in ... |
| CVE-2025-4203 | HIGH | 7.5 | 0.3% | Oct 25, 2025 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() fun... |
| CVE-2025-10488 | HIGH | 8.1 | 0.8% | Oct 25, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-12095 | HIGH | 8.8 | 0.2% | Oct 25, 2025 | The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-11238 | HIGH | 7.2 | 0.2% | Oct 25, 2025 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions ... |
| CVE-2025-34503 | HIGH | 7 | 0.1% | Oct 24, 2025 | Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker ... |
| CVE-2025-34502 | HIGH | 7 | 0.2% | Oct 24, 2025 | Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. ... |
| CVE-2025-34500 | HIGH | 7 | 0.1% | Oct 24, 2025 | Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit... |
| CVE-2025-4106 | HIGH | 8.9 | 0.3% | Oct 24, 2025 | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable ... |
| CVE-2025-34293 | HIGH | 8.6 | 0.4% | Oct 24, 2025 | GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API... |
| CVE-2025-60954 | HIGH | 8.3 | 0.4% | Oct 24, 2025 | Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexit... |
| CVE-2025-62716 | HIGH | 8.1 | 0.3% | Oct 24, 2025 | Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_pa... |
| CVE-2025-60735 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function |
| CVE-2025-60731 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function |
| CVE-2025-60730 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function |
| CVE-2025-62714 | HIGH | 8.7 | 0.6% | Oct 24, 2025 | Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project.... |
| CVE-2025-60801 | HIGH | 8.2 | 0.4% | Oct 24, 2025 | jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via ... |
| CVE-2025-60566 | HIGH | 7.5 | 0.4% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60565 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60564 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60563 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60562 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formW... |
| CVE-2025-60561 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now