2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64195 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64194 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma ed... |
| CVE-2025-60075 | HIGH | 7.1 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflecte... |
| CVE-2025-58939 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site R... |
| CVE-2025-58711 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Pro... |
| CVE-2025-12058 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vuln... |
| CVE-2025-11702 | HIGH | 8.8 | 0.6% | Oct 29, 2025 | GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before... |
| CVE-2025-9544 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capab... |
| CVE-2025-62776 | HIGH | 8.4 | 0.1% | Oct 29, 2025 | The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurel... |
| CVE-2025-49042 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooComm... |
| CVE-2025-11705 | MEDIUM | 6.5 | 0.6% | Oct 29, 2025 | The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all vers... |
| CVE-2025-64296 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Inco... |
| CVE-2025-64162 | — | — | — | Oct 29, 2025 | Rejected reason: Not used |
| CVE-2025-64161 | — | — | — | Oct 29, 2025 | Rejected reason: Not used |
| CVE-2025-64160 | — | — | — | Oct 29, 2025 | Rejected reason: Not used |
| CVE-2025-64159 | — | — | — | Oct 29, 2025 | Rejected reason: Not used |
| CVE-2025-64158 | — | — | — | Oct 29, 2025 | Rejected reason: Not used |
| CVE-2025-57931 | MEDIUM | 5.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.Thi... |
| CVE-2025-4665 | CRITICAL | 9.6 | 0.3% | Oct 29, 2025 | WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injectio... |
| CVE-2025-64095 | CRITICAL | 9.8 | 44.7% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-64094 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-62802 | MEDIUM | 4.3 | 0.2% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-62801 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerabi... |
| CVE-2025-62800 | MEDIUM | 6.1 | 0.3% | Oct 28, 2025 | FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site sc... |
| CVE-2025-62798 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now