2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41724 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process wi... |
| CVE-2025-41723 | CRITICAL | 9.8 | 1.2% | Oct 22, 2025 | The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the ... |
| CVE-2025-41722 | HIGH | 7.5 | 0.2% | Oct 22, 2025 | The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attac... |
| CVE-2025-41721 | LOW | 2.7 | 0.2% | Oct 22, 2025 | A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralizat... |
| CVE-2025-41720 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserv... |
| CVE-2025-41719 | HIGH | 8.8 | 0.5% | Oct 22, 2025 | A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsuppor... |
| CVE-2025-12033 | MEDIUM | 4.4 | 0.2% | Oct 22, 2025 | The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl... |
| CVE-2025-10588 | MEDIUM | 4.3 | 0.1% | Oct 22, 2025 | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forger... |
| CVE-2025-10570 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all ... |
| CVE-2025-5983 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags. |
| CVE-2025-10651 | MEDIUM | 5.5 | 0.2% | Oct 22, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in... |
| CVE-2025-10638 | MEDIUM | 5.3 | 0.2% | Oct 22, 2025 | The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allo... |
| CVE-2025-62775 | HIGH | 8 | 0.3% | Oct 22, 2025 | Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password. |
| CVE-2025-62774 | LOW | 3.1 | 0.2% | Oct 22, 2025 | On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps. |
| CVE-2025-62773 | LOW | 2.4 | 0.2% | Oct 22, 2025 | Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator. |
| CVE-2025-62772 | LOW | 3.1 | 0.1% | Oct 22, 2025 | On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases. |
| CVE-2025-62771 | HIGH | 7.5 | 0.1% | Oct 22, 2025 | Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks. |
| CVE-2025-22167 | MEDIUM | 6.5 | 0.4% | Oct 22, 2025 | This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain ... |
| CVE-2025-61756 | HIGH | 7.5 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2025-62661 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth... |
| CVE-2025-62641 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62592 | MEDIUM | 6 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62591 | MEDIUM | 6 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62590 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-62589 | HIGH | 8.2 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now