2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54479 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests ... |
| CVE-2025-53868 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by... |
| CVE-2025-53856 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object use... |
| CVE-2025-53521 | CRITICAL | 9.8 | 2.2% | Oct 15, 2025 | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex... |
| CVE-2025-53474 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Ma... |
| CVE-2025-48008 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with ... |
| CVE-2025-47150 | HIGH | 7.1 | 0.3% | Oct 15, 2025 | When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory... |
| CVE-2025-47148 | HIGH | 7.1 | 0.4% | Oct 15, 2025 | When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Ident... |
| CVE-2025-46706 | HIGH | 8.7 | 0.4% | Oct 15, 2025 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an ... |
| CVE-2025-41430 | HIGH | 8.7 | 0.3% | Oct 15, 2025 | When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termi... |
| CVE-2025-9640 | MEDIUM | 4.3 | 0.4% | Oct 15, 2025 | A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into altern... |
| CVE-2025-10869 | MEDIUM | 6.1 | 0.2% | Oct 15, 2025 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co... |
| CVE-2025-55082 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read i... |
| CVE-2025-55081 | CRITICAL | 9.1 | 0.3% | Oct 15, 2025 | In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was... |
| CVE-2025-9967 | CRITICAL | 9.8 | 0.4% | Oct 15, 2025 | The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve... |
| CVE-2025-11728 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification ... |
| CVE-2025-11722 | HIGH | 7.5 | 0.6% | Oct 15, 2025 | The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all ... |
| CVE-2025-11701 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ... |
| CVE-2025-11692 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c... |
| CVE-2025-11365 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google... |
| CVE-2025-11196 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu... |
| CVE-2025-11177 | HIGH | 7.5 | 0.4% | Oct 15, 2025 | The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an... |
| CVE-2025-10754 | HIGH | 7.2 | 0.6% | Oct 15, 2025 | The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-10743 | HIGH | 7.5 | 0.3% | Oct 15, 2025 | The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi... |
| CVE-2025-10730 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now