2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11889 | HIGH | 7.2 | 0.6% | Oct 24, 2025 | The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2025-11504 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9... |
| CVE-2025-62868 | HIGH | 8.1 | 0.4% | Oct 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62254 | HIGH | 7.5 | 0.5% | Oct 23, 2025 | The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 th... |
| CVE-2025-58429 | HIGH | 8.3 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-62688 | HIGH | 7.1 | 0.1% | Oct 23, 2025 | An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v... |
| CVE-2025-62498 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The ... |
| CVE-2025-61977 | HIGH | 7.3 | 0.1% | Oct 23, 2025 | A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve... |
| CVE-2025-59500 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network... |
| CVE-2025-58456 | HIGH | 8.2 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab... |
| CVE-2025-58078 | HIGH | 8.3 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera... |
| CVE-2025-12100 | HIGH | 8.8 | 0.1% | Oct 23, 2025 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a... |
| CVE-2025-55067 | HIGH | 7.1 | 0.4% | Oct 23, 2025 | The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th... |
| CVE-2025-54964 | HIGH | 8.4 | 0.3% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi... |
| CVE-2025-12044 | HIGH | 7.5 | 0.5% | Oct 23, 2025 | Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload... |
| CVE-2025-6980 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | Captive Portal can expose sensitive information |
| CVE-2025-6979 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | Captive Portal can allow authentication bypass |
| CVE-2025-6978 | HIGH | 7.2 | 11.7% | Oct 23, 2025 | Diagnostics command injection vulnerability |
| CVE-2025-54808 | HIGH | 7.8 | 0.2% | Oct 23, 2025 | Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat... |
| CVE-2025-23352 | HIGH | 7.8 | 0.2% | Oct 23, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali... |
| CVE-2025-23347 | HIGH | 7.8 | 0.1% | Oct 23, 2025 | NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e... |
| CVE-2025-11621 | HIGH | 8.1 | 0.5% | Oct 23, 2025 | Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co... |
| CVE-2025-62713 | HIGH | 7.2 | 0.7% | Oct 23, 2025 | Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati... |
| CVE-2025-62169 | HIGH | 8.1 | 0.4% | Oct 23, 2025 | OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th... |
| CVE-2025-59048 | HIGH | 8.1 | 0.2% | Oct 23, 2025 | OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now