2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-60015MEDIUM6.9An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.  Note: Softw...
CVE-2025-60013MEDIUM4.6When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with sp...
CVE-2025-59483MEDIUM6.5A validation vulnerability exists in an undisclosed URL in the Configuration utility.  Note: Software versions which hav...
CVE-2025-59268MEDIUM6.9On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthent...
CVE-2025-58474MEDIUM5.3When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an...
CVE-2025-58424MEDIUM6.3On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which d...
CVE-2025-58153MEDIUM5.9Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-S...
CVE-2025-54805MEDIUM6.5When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can ...
CVE-2025-54755MEDIUM4.9A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access file...
CVE-2025-9640MEDIUM4.3A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into altern...
CVE-2025-10869MEDIUM6.1Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co...
CVE-2025-55082MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read i...
CVE-2025-11728MEDIUM5.3The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification ...
CVE-2025-11701MEDIUM5.3The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2025-11692MEDIUM5.3The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c...
CVE-2025-11365MEDIUM6.5The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google...
CVE-2025-11196MEDIUM4.3The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu...
CVE-2025-10730MEDIUM6.5The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver...
CVE-2025-10682MEDIUM6.5The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to ...
CVE-2025-10660MEDIUM6.5The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, ...
CVE-2025-10648MEDIUM5.3The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due t...
CVE-2025-10575MEDIUM6.5The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand...
CVE-2025-10486MEDIUM5.3The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2025-10312MEDIUM4.3The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-10310MEDIUM4.9The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now