2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48082 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Esca... |
| CVE-2025-39534 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Di... |
| CVE-2025-32657 | HIGH | 7.5 | 0.6% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32283 | HIGH | 8.8 | 0.6% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue af... |
| CVE-2025-31634 | HIGH | 8.8 | 0.6% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue a... |
| CVE-2025-30944 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality ... |
| CVE-2025-11965 | HIGH | 7.5 | 0.5% | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to h... |
| CVE-2025-61035 | HIGH | 7.7 | 0.1% | Oct 22, 2025 | The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file... |
| CVE-2025-11086 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e... |
| CVE-2025-41110 | HIGH | 8.8 | 0.2% | Oct 22, 2025 | Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an ... |
| CVE-2025-41724 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process wi... |
| CVE-2025-41722 | HIGH | 7.5 | 0.2% | Oct 22, 2025 | The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attac... |
| CVE-2025-41719 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsuppor... |
| CVE-2025-62775 | HIGH | 8 | 0.3% | Oct 22, 2025 | Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password. |
| CVE-2025-62771 | HIGH | 7.5 | 0.1% | Oct 22, 2025 | Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks. |
| CVE-2025-61756 | HIGH | 7.5 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2025-62641 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62590 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62589 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62588 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62587 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62290 | HIGH | 7.2 | 0.4% | Oct 21, 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The suppor... |
| CVE-2025-61763 | HIGH | 8.1 | 0.2% | Oct 21, 2025 | Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.... |
| CVE-2025-61760 | HIGH | 7.5 | 0.1% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-61752 | HIGH | 7.5 | 0.4% | Oct 21, 2025 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now