2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58096HIGH8.2When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undi...
CVE-2025-55670HIGH7.1On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause th...
CVE-2025-55669HIGH8.7When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server...
CVE-2025-55036HIGH8.7When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is e...
CVE-2025-54858HIGH8.7When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed ...
CVE-2025-54854HIGH8.7When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclos...
CVE-2025-54479HIGH8.7When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests ...
CVE-2025-53868HIGH8.7When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by...
CVE-2025-53856HIGH8.7When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object use...
CVE-2025-53474HIGH8.7When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Ma...
CVE-2025-48008HIGH8.7When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with ...
CVE-2025-47150HIGH7.1When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory...
CVE-2025-47148HIGH7.1When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Ident...
CVE-2025-46706HIGH8.7When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an ...
CVE-2025-41430HIGH8.7When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termi...
CVE-2025-11722HIGH7.5The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all ...
CVE-2025-11177HIGH7.5The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an...
CVE-2025-10754HIGH7.2The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-10743HIGH7.5The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi...
CVE-2025-10313HIGH7.2The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin...
CVE-2025-10299HIGH8.8The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du...
CVE-2025-10293HIGH8.8The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta...
CVE-2025-10051HIGH7.2The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-61941HIGH8.6A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered b...
CVE-2025-40000HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_ki...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now