2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43994 | HIGH | 7.5 | 0.6% | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Fun... |
| CVE-2025-11145 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Informa... |
| CVE-2025-46183 | HIGH | 8.2 | 0.3% | Oct 24, 2025 | The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker ... |
| CVE-2025-40024 | HIGH | 7.8 | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost... |
| CVE-2025-40018 | HIGH | 7.8 | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns clean... |
| CVE-2025-10861 | HIGH | 7.5 | 0.4% | Oct 24, 2025 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr... |
| CVE-2025-36361 | HIGH | 8.8 | 0.2% | Oct 24, 2025 | IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user ... |
| CVE-2025-10680 | HIGH | 8.8 | 6.9% | Oct 24, 2025 | OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell comma... |
| CVE-2025-12028 | HIGH | 8.8 | 0.2% | Oct 24, 2025 | The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5... |
| CVE-2025-11889 | HIGH | 7.2 | 0.6% | Oct 24, 2025 | The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2025-11504 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9... |
| CVE-2025-62868 | HIGH | 8.1 | 0.5% | Oct 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62254 | HIGH | 7.5 | 0.5% | Oct 23, 2025 | The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 th... |
| CVE-2025-58429 | HIGH | 8.3 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-62688 | HIGH | 7.1 | 0.1% | Oct 23, 2025 | An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v... |
| CVE-2025-62498 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The ... |
| CVE-2025-61977 | HIGH | 7.3 | 0.1% | Oct 23, 2025 | A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve... |
| CVE-2025-59500 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network... |
| CVE-2025-58456 | HIGH | 8.2 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab... |
| CVE-2025-58078 | HIGH | 8.3 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera... |
| CVE-2025-12100 | HIGH | 8.8 | 0.1% | Oct 23, 2025 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a... |
| CVE-2025-55067 | HIGH | 7.1 | 0.4% | Oct 23, 2025 | The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th... |
| CVE-2025-54964 | HIGH | 8.4 | 0.3% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi... |
| CVE-2025-12044 | HIGH | 7.5 | 0.5% | Oct 23, 2025 | Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload... |
| CVE-2025-6980 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | Captive Portal can expose sensitive information |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now