2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54479HIGH8.7When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests ...
CVE-2025-53868HIGH8.7When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by...
CVE-2025-53856HIGH8.7When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object use...
CVE-2025-53521CRITICAL9.8When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex...
CVE-2025-53474HIGH8.7When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Ma...
CVE-2025-48008HIGH8.7When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with ...
CVE-2025-47150HIGH7.1When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory...
CVE-2025-47148HIGH7.1When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Ident...
CVE-2025-46706HIGH8.7When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an ...
CVE-2025-41430HIGH8.7When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termi...
CVE-2025-9640MEDIUM4.3A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into altern...
CVE-2025-10869MEDIUM6.1Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co...
CVE-2025-55082MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read i...
CVE-2025-55081CRITICAL9.1In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was...
CVE-2025-9967CRITICAL9.8The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve...
CVE-2025-11728MEDIUM5.3The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification ...
CVE-2025-11722HIGH7.5The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all ...
CVE-2025-11701MEDIUM5.3The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2025-11692MEDIUM5.3The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c...
CVE-2025-11365MEDIUM6.5The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google...
CVE-2025-11196MEDIUM4.3The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu...
CVE-2025-11177HIGH7.5The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an...
CVE-2025-10754HIGH7.2The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-10743HIGH7.5The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi...
CVE-2025-10730MEDIUM6.5The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now