2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60334 | HIGH | 7.5 | 0.5% | Oct 22, 2025 | TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBa... |
| CVE-2025-60333 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiF... |
| CVE-2025-40780 | HIGH | 8.6 | 0.5% | Oct 22, 2025 | In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible f... |
| CVE-2025-40778 | HIGH | 8.6 | 0.5% | Oct 22, 2025 | Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject for... |
| CVE-2025-62606 | HIGH | 8.8 | 0.3% | Oct 22, 2025 | my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to ... |
| CVE-2025-62604 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval o... |
| CVE-2025-62526 | HIGH | 7.8 | 0.2% | Oct 22, 2025 | OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap ... |
| CVE-2025-62525 | HIGH | 8.8 | 0.2% | Oct 22, 2025 | OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read... |
| CVE-2025-62054 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62029 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-62022 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through ... |
| CVE-2025-62020 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network... |
| CVE-2025-62015 | HIGH | 7.6 | 0.3% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Josh Kohlbach Adva... |
| CVE-2025-62008 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.T... |
| CVE-2025-62007 | HIGH | 8.8 | 0.3% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This ... |
| CVE-2025-62005 | HIGH | 7.1 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships all... |
| CVE-2025-60332 | HIGH | 7.5 | 4.6% | Oct 22, 2025 | A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to caus... |
| CVE-2025-60331 | HIGH | 7.5 | 0.6% | Oct 22, 2025 | D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_S... |
| CVE-2025-60246 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weissmike Simple F... |
| CVE-2025-60234 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.... |
| CVE-2025-60228 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue ... |
| CVE-2025-60227 | HIGH | 8.6 | 0.5% | Oct 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pi... |
| CVE-2025-60222 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows... |
| CVE-2025-60217 | HIGH | 7.7 | 0.4% | Oct 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt... |
| CVE-2025-60215 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects K... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now