2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60332 | HIGH | 7.5 | 4.6% | Oct 22, 2025 | A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to caus... |
| CVE-2025-60331 | HIGH | 7.5 | 0.6% | Oct 22, 2025 | D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_S... |
| CVE-2025-60246 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weissmike Simple F... |
| CVE-2025-60234 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.... |
| CVE-2025-60228 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue ... |
| CVE-2025-60227 | HIGH | 8.6 | 0.5% | Oct 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pi... |
| CVE-2025-60222 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows... |
| CVE-2025-60217 | HIGH | 7.7 | 0.4% | Oct 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ypromo PT Luxa Addons pt... |
| CVE-2025-60215 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects K... |
| CVE-2025-60212 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VED... |
| CVE-2025-60211 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields ... |
| CVE-2025-60208 | HIGH | 8.8 | 0.2% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-option... |
| CVE-2025-60168 | HIGH | 7.1 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in integrationshotelrunner HotelRunner Booking Widget hotelrunner allows... |
| CVE-2025-60132 | HIGH | 7.1 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.Thi... |
| CVE-2025-60041 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all ... |
| CVE-2025-59580 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.T... |
| CVE-2025-59579 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows ... |
| CVE-2025-59571 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkSco... |
| CVE-2025-59566 | HIGH | 7.7 | 0.4% | Oct 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (the... |
| CVE-2025-59564 | HIGH | 8.1 | 0.5% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59558 | HIGH | 8.1 | 0.5% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59555 | HIGH | 8.1 | 0.5% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59550 | HIGH | 8.1 | 0.5% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59006 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Easy Wooc... |
| CVE-2025-59004 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pco_58 WC Return p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now