2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58096 | HIGH | 8.2 | 0.3% | Oct 15, 2025 | When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undi... |
| CVE-2025-55670 | HIGH | 7.1 | 0.3% | Oct 15, 2025 | On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause th... |
| CVE-2025-55669 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server... |
| CVE-2025-55036 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is e... |
| CVE-2025-54858 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed ... |
| CVE-2025-54854 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclos... |
| CVE-2025-54479 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests ... |
| CVE-2025-53868 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by... |
| CVE-2025-53856 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object use... |
| CVE-2025-53474 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Ma... |
| CVE-2025-48008 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with ... |
| CVE-2025-47150 | HIGH | 7.1 | 0.3% | Oct 15, 2025 | When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory... |
| CVE-2025-47148 | HIGH | 7.1 | 0.4% | Oct 15, 2025 | When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Ident... |
| CVE-2025-46706 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an ... |
| CVE-2025-41430 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termi... |
| CVE-2025-11722 | HIGH | 7.5 | 0.6% | Oct 15, 2025 | The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all ... |
| CVE-2025-11177 | HIGH | 7.5 | 0.4% | Oct 15, 2025 | The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an... |
| CVE-2025-10754 | HIGH | 7.2 | 0.6% | Oct 15, 2025 | The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-10743 | HIGH | 7.5 | 0.3% | Oct 15, 2025 | The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi... |
| CVE-2025-10313 | HIGH | 7.2 | 0.3% | Oct 15, 2025 | The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin... |
| CVE-2025-10299 | HIGH | 8.8 | 0.3% | Oct 15, 2025 | The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du... |
| CVE-2025-10293 | HIGH | 8.8 | 0.3% | Oct 15, 2025 | The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta... |
| CVE-2025-10051 | HIGH | 7.2 | 0.6% | Oct 15, 2025 | The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-61941 | HIGH | 8.6 | 0.5% | Oct 15, 2025 | A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered b... |
| CVE-2025-40000 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_ki... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now