2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10870 | CRITICAL | 9.3 | 0.2% | Nov 7, 2025 | SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete datab... |
| CVE-2025-64338 | CRITICAL | 9 | 0.4% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular use... |
| CVE-2025-12352 | CRITICAL | 9.8 | 0.7% | Nov 7, 2025 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-64180 | CRITICAL | 10 | 0.3% | Nov 7, 2025 | Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vul... |
| CVE-2025-11546 | CRITICAL | 9.3 | 0.4% | Nov 7, 2025 | CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, C... |
| CVE-2025-62630 | CRITICAL | 9.8 | 0.6% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories... |
| CVE-2025-59171 | CRITICAL | 9.8 | 0.6% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories... |
| CVE-2025-12488 | CRITICAL | 9.8 | 0.8% | Nov 6, 2025 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This... |
| CVE-2025-12487 | CRITICAL | 9.8 | 0.8% | Nov 6, 2025 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This... |
| CVE-2025-27918 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.... |
| CVE-2025-6327 | CRITICAL | 10 | 0.5% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons al... |
| CVE-2025-6325 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Es... |
| CVE-2025-62065 | CRITICAL | 9.9 | 0.3% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue aff... |
| CVE-2025-62064 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows... |
| CVE-2025-62047 | CRITICAL | 9.9 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects ... |
| CVE-2025-62016 | CRITICAL | 9.9 | 0.3% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from... |
| CVE-2025-60245 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injecti... |
| CVE-2025-60243 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-c... |
| CVE-2025-60235 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium)... |
| CVE-2025-60207 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce ... |
| CVE-2025-60195 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalatio... |
| CVE-2025-58998 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue... |
| CVE-2025-58996 | CRITICAL | 9.1 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows... |
| CVE-2025-58636 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows O... |
| CVE-2025-58627 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now