2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56219 | HIGH | 7.1 | 0.3% | Oct 20, 2025 | Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin... |
| CVE-2025-62577 | HIGH | 8.8 | 0.2% | Oct 20, 2025 | ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged ... |
| CVE-2025-11944 | HIGH | 7.2 | 0.5% | Oct 19, 2025 | A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control... |
| CVE-2025-11941 | HIGH | 8.1 | 0.8% | Oct 19, 2025 | A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php... |
| CVE-2025-11940 | HIGH | 7.3 | 0.2% | Oct 19, 2025 | A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of ... |
| CVE-2025-11939 | HIGH | 7.2 | 0.9% | Oct 19, 2025 | A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu... |
| CVE-2025-11938 | HIGH | 8.1 | 0.7% | Oct 19, 2025 | A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se... |
| CVE-2025-47410 | HIGH | 8.8 | 0.3% | Oct 18, 2025 | Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all... |
| CVE-2025-9890 | HIGH | 8.8 | 0.4% | Oct 18, 2025 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-5555 | HIGH | 7.8 | 0.2% | Oct 18, 2025 | A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in th... |
| CVE-2025-11691 | HIGH | 7.5 | 0.4% | Oct 18, 2025 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PP... |
| CVE-2025-11517 | HIGH | 7.5 | 0.4% | Oct 18, 2025 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu... |
| CVE-2025-62646 | HIGH | 7.7 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the st... |
| CVE-2025-62644 | HIGH | 7.7 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares... |
| CVE-2025-62643 | HIGH | 8.6 | 0.3% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in ... |
| CVE-2025-62642 | HIGH | 8.6 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign... |
| CVE-2025-11914 | HIGH | 7.5 | 0.8% | Oct 17, 2025 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function ... |
| CVE-2025-11912 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file ... |
| CVE-2025-11911 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t... |
| CVE-2025-11910 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct... |
| CVE-2025-11909 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi... |
| CVE-2025-11908 | HIGH | 8.8 | 0.5% | Oct 17, 2025 | A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f... |
| CVE-2025-62422 | HIGH | 8.8 | 0.5% | Oct 17, 2025 | DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datas... |
| CVE-2025-62420 | HIGH | 8.8 | 0.9% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vuln... |
| CVE-2025-62419 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vuln... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now