2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12598 | CRITICAL | 9.8 | 0.3% | Nov 2, 2025 | A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function ... |
| CVE-2025-12597 | CRITICAL | 9.8 | 0.3% | Nov 2, 2025 | A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability i... |
| CVE-2025-12596 | CRITICAL | 9.8 | 1.2% | Nov 2, 2025 | A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of ... |
| CVE-2025-12595 | CRITICAL | 9.8 | 1.0% | Nov 2, 2025 | A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /gofor... |
| CVE-2025-12603 | CRITICAL | 9.8 | 0.2% | Nov 1, 2025 | /etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12602 | CRITICAL | 9.8 | 0.2% | Nov 1, 2025 | /etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1... |
| CVE-2025-12600 | CRITICAL | 9.8 | 0.3% | Nov 1, 2025 | Web UI Malfunction when setting unexpected locale via API.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1... |
| CVE-2025-12599 | CRITICAL | 9.8 | 0.4% | Nov 1, 2025 | Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-I... |
| CVE-2025-11499 | CRITICAL | 9.8 | 1.0% | Nov 1, 2025 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ... |
| CVE-2025-11833 | CRITICAL | 9.8 | 51.0% | Nov 1, 2025 | The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to... |
| CVE-2025-29270 | CRITICAL | 10 | 0.3% | Oct 31, 2025 | Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows at... |
| CVE-2025-12554 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12553 | CRITICAL | 9.8 | 0.2% | Oct 31, 2025 | Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12552 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-64388 | CRITICAL | 9.2 | 0.3% | Oct 31, 2025 | Denial of service of the web server through specific requests to this protocol |
| CVE-2025-64385 | CRITICAL | 9.2 | 0.5% | Oct 31, 2025 | The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the ... |
| CVE-2025-57108 | CRITICAL | 9.8 | 0.4% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader.... |
| CVE-2025-6520 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BA... |
| CVE-2025-8489 | CRITICAL | 9.8 | 9.1% | Oct 31, 2025 | The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vu... |
| CVE-2025-5397 | CRITICAL | 9.8 | 1.0% | Oct 31, 2025 | The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.... |
| CVE-2025-52665 | CRITICAL | 10 | 41.0% | Oct 31, 2025 | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat... |
| CVE-2025-48983 | CRITICAL | 9.9 | 0.8% | Oct 31, 2025 | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the ... |
| CVE-2025-34277 | CRITICAL | 9.8 | 2.0% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID value... |
| CVE-2025-34274 | CRITICAL | 9.8 | 1.9% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs... |
| CVE-2025-34271 | CRITICAL | 9.8 | 0.7% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now