2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58277 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect... |
| CVE-2025-9560 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_news... |
| CVE-2025-11380 | MEDIUM | 5.9 | 0.4% | Oct 11, 2025 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u... |
| CVE-2025-54654 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service... |
| CVE-2025-9554 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*. |
| CVE-2025-9553 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*. |
| CVE-2025-9552 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With... |
| CVE-2025-9551 | MEDIUM | 6.5 | 0.4% | Oct 10, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.Thi... |
| CVE-2025-9550 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo... |
| CVE-2025-9549 | MEDIUM | 6.5 | 0.2% | Oct 10, 2025 | Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 befo... |
| CVE-2025-52885 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulne... |
| CVE-2025-52647 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Head... |
| CVE-2025-11626 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service |
| CVE-2025-61912 | MEDIUM | 5.3 | 0.4% | Oct 10, 2025 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn... |
| CVE-2025-61911 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the san... |
| CVE-2025-62245 | MEDIUM | 4.3 | 0.2% | Oct 10, 2025 | Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 thr... |
| CVE-2025-62158 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system d... |
| CVE-2025-61925 | MEDIUM | 6.5 | 0.4% | Oct 10, 2025 | Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `... |
| CVE-2025-61505 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-co... |
| CVE-2025-60838 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted... |
| CVE-2025-60268 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the sa... |
| CVE-2025-11618 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer derefer... |
| CVE-2025-11617 | MEDIUM | 5.4 | 0.3% | Oct 10, 2025 | A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when rec... |
| CVE-2025-11616 | MEDIUM | 5.4 | 0.3% | Oct 10, 2025 | A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when r... |
| CVE-2025-11580 | MEDIUM | 5.5 | 1.0% | Oct 10, 2025 | A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This mani... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now