2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12094 | MEDIUM | 5.3 | 0.3% | Oct 31, 2025 | The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to... |
| CVE-2025-8385 | MEDIUM | 6.8 | 0.4% | Oct 31, 2025 | The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du... |
| CVE-2025-6520 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BA... |
| CVE-2025-10897 | HIGH | 8.6 | 1.8% | Oct 31, 2025 | The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi... |
| CVE-2025-8489 | CRITICAL | 9.8 | 9.1% | Oct 31, 2025 | The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vu... |
| CVE-2025-7846 | HIGH | 8.8 | 0.6% | Oct 31, 2025 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2025-63675 | HIGH | 8.8 | 0.2% | Oct 31, 2025 | cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt... |
| CVE-2025-5397 | CRITICAL | 9.8 | 1.0% | Oct 31, 2025 | The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.... |
| CVE-2025-58152 | MEDIUM | 6.9 | 0.3% | Oct 31, 2025 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i... |
| CVE-2025-54763 | HIGH | 8.6 | 1.3% | Oct 31, 2025 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user... |
| CVE-2025-11191 | MEDIUM | 5.3 | 0.3% | Oct 31, 2025 | The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the cr... |
| CVE-2025-11975 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)... |
| CVE-2025-11806 | MEDIUM | 6.4 | 0.2% | Oct 31, 2025 | The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver... |
| CVE-2025-23050 | LOW | 3.1 | 0.2% | Oct 31, 2025 | QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (o... |
| CVE-2025-8849 | HIGH | 7.5 | 0.3% | Oct 31, 2025 | LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api... |
| CVE-2025-6176 | HIGH | 7.5 | 0.5% | Oct 31, 2025 | Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio... |
| CVE-2025-52665 | CRITICAL | 10 | 41.0% | Oct 31, 2025 | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat... |
| CVE-2025-52664 | HIGH | 8.8 | 0.9% | Oct 31, 2025 | SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo... |
| CVE-2025-52663 | HIGH | 7.3 | 0.2% | Oct 31, 2025 | A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention... |
| CVE-2025-48984 | HIGH | 8.8 | 1.0% | Oct 31, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| CVE-2025-48983 | CRITICAL | 9.9 | 0.8% | Oct 31, 2025 | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the ... |
| CVE-2025-48982 | HIGH | 7.8 | 0.2% | Oct 31, 2025 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator ... |
| CVE-2025-48980 | MEDIUM | 6.5 | 0.3% | Oct 31, 2025 | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split Vie... |
| CVE-2025-27208 | MEDIUM | 6.1 | 1.4% | Oct 31, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker c... |
| CVE-2025-34298 | HIGH | 8.8 | 0.6% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now