2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12597 | CRITICAL | 9.8 | 0.3% | Nov 2, 2025 | A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability i... |
| CVE-2025-12596 | CRITICAL | 9.8 | 1.2% | Nov 2, 2025 | A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of ... |
| CVE-2025-12595 | CRITICAL | 9.8 | 1.0% | Nov 2, 2025 | A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /gofor... |
| CVE-2025-12594 | HIGH | 7.2 | 0.4% | Nov 2, 2025 | A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown... |
| CVE-2025-12593 | HIGH | 7.2 | 0.4% | Nov 2, 2025 | A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u... |
| CVE-2025-12603 | CRITICAL | 9.8 | 0.2% | Nov 1, 2025 | /etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12602 | CRITICAL | 9.8 | 0.2% | Nov 1, 2025 | /etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1... |
| CVE-2025-12601 | HIGH | 7.5 | 0.3% | Nov 1, 2025 | Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12600 | CRITICAL | 9.8 | 0.3% | Nov 1, 2025 | Web UI Malfunction when setting unexpected locale via API.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1... |
| CVE-2025-12599 | CRITICAL | 9.8 | 0.4% | Nov 1, 2025 | Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-I... |
| CVE-2025-36367 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authoriz... |
| CVE-2025-6990 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via ... |
| CVE-2025-6988 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a... |
| CVE-2025-6574 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-12171 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
| CVE-2025-12137 | MEDIUM | 4.9 | 0.4% | Nov 1, 2025 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Re... |
| CVE-2025-11755 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar... |
| CVE-2025-11499 | CRITICAL | 9.8 | 1.0% | Nov 1, 2025 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ... |
| CVE-2025-10487 | HIGH | 7.3 | 0.4% | Nov 1, 2025 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up t... |
| CVE-2025-12180 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T... |
| CVE-2025-12090 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-12038 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability c... |
| CVE-2025-11983 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9.... |
| CVE-2025-11740 | MEDIUM | 6.5 | 0.2% | Nov 1, 2025 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to... |
| CVE-2025-11502 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now