2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64360 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64359 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64358 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows E... |
| CVE-2025-64357 | MEDIUM | 4.3 | 0.1% | Oct 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allow... |
| CVE-2025-64356 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorre... |
| CVE-2025-64354 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gut... |
| CVE-2025-64353 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P... |
| CVE-2025-64352 | LOW | 2.7 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite al... |
| CVE-2025-64351 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows R... |
| CVE-2025-64350 | LOW | 3.8 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Config... |
| CVE-2025-58149 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the... |
| CVE-2025-58148 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-58147 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-40603 | MEDIUM | 4.5 | 0.4% | Oct 31, 2025 | A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, aut... |
| CVE-2025-11602 | MEDIUM | 6.3 | 0.3% | Oct 31, 2025 | Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obta... |
| CVE-2025-40106 | — | — | 0.2% | Oct 31, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() T... |
| CVE-2025-12115 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi... |
| CVE-2025-12041 | MEDIUM | 5.3 | 0.2% | Oct 31, 2025 | The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2025-11843 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an accoun... |
| CVE-2025-8383 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4.... |
| CVE-2025-62232 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f... |
| CVE-2025-30191 | MEDIUM | 5.4 | 0.2% | Oct 31, 2025 | Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended act... |
| CVE-2025-30189 | HIGH | 7.4 | 0.5% | Oct 31, 2025 | When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached ... |
| CVE-2025-30188 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform... |
| CVE-2025-12175 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now