2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60015 | MEDIUM | 6.9 | 0.2% | Oct 15, 2025 | An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Softw... |
| CVE-2025-60013 | MEDIUM | 4.6 | 0.2% | Oct 15, 2025 | When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with sp... |
| CVE-2025-59483 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which hav... |
| CVE-2025-59268 | MEDIUM | 6.9 | 0.4% | Oct 15, 2025 | On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthent... |
| CVE-2025-58474 | MEDIUM | 5.3 | 0.4% | Oct 15, 2025 | When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an... |
| CVE-2025-58424 | MEDIUM | 6.3 | 0.2% | Oct 15, 2025 | On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which d... |
| CVE-2025-58153 | MEDIUM | 5.9 | 0.2% | Oct 15, 2025 | Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-S... |
| CVE-2025-54805 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can ... |
| CVE-2025-54755 | MEDIUM | 4.9 | 1.1% | Oct 15, 2025 | A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access file... |
| CVE-2025-9640 | MEDIUM | 4.3 | 0.4% | Oct 15, 2025 | A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into altern... |
| CVE-2025-10869 | MEDIUM | 6.1 | 0.2% | Oct 15, 2025 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co... |
| CVE-2025-55082 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read i... |
| CVE-2025-11728 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification ... |
| CVE-2025-11701 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ... |
| CVE-2025-11692 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c... |
| CVE-2025-11365 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google... |
| CVE-2025-11196 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu... |
| CVE-2025-10730 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver... |
| CVE-2025-10682 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to ... |
| CVE-2025-10660 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, ... |
| CVE-2025-10648 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due t... |
| CVE-2025-10575 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand... |
| CVE-2025-10486 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2025-10312 | MEDIUM | 4.3 | 0.1% | Oct 15, 2025 | The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-10310 | MEDIUM | 4.9 | 0.3% | Oct 15, 2025 | The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now