2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11378 | MEDIUM | 5.4 | 0.3% | Oct 18, 2025 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized... |
| CVE-2025-62640 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62639 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62638 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62637 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62636 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62635 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62634 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62633 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62632 | — | — | — | Oct 18, 2025 | Rejected reason: Not used |
| CVE-2025-62655 | LOW | 2.1 | 0.2% | Oct 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun... |
| CVE-2025-62654 | LOW | 2 | 0.3% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62653 | LOW | 2 | 0.3% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62652 | MEDIUM | 5.9 | 0.4% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62651 | MEDIUM | 5.8 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for th... |
| CVE-2025-62650 | CRITICAL | 9.9 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for... |
| CVE-2025-62649 | MEDIUM | 5.8 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for... |
| CVE-2025-62648 | MEDIUM | 5.8 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive ... |
| CVE-2025-62647 | MEDIUM | 5.8 | 0.3% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning ... |
| CVE-2025-62646 | HIGH | 7.7 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the st... |
| CVE-2025-62645 | CRITICAL | 9.9 | 0.7% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t... |
| CVE-2025-62644 | HIGH | 7.7 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares... |
| CVE-2025-62643 | HIGH | 8.6 | 0.3% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in ... |
| CVE-2025-62642 | HIGH | 8.6 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign... |
| CVE-2025-62515 | CRITICAL | 9.8 | 0.8% | Oct 17, 2025 | pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now