2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58277 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect... |
| CVE-2025-9560 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_news... |
| CVE-2025-11380 | MEDIUM | 5.9 | 0.4% | Oct 11, 2025 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u... |
| CVE-2025-54654 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service... |
| CVE-2025-31718 | HIGH | 7.5 | 0.6% | Oct 11, 2025 | In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of pri... |
| CVE-2025-31717 | HIGH | 7.5 | 0.6% | Oct 11, 2025 | In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2025-11590 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown func... |
| CVE-2025-9554 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*. |
| CVE-2025-9553 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*. |
| CVE-2025-9552 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With... |
| CVE-2025-9551 | MEDIUM | 6.5 | 0.4% | Oct 10, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.Thi... |
| CVE-2025-9550 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo... |
| CVE-2025-9549 | MEDIUM | 6.5 | 0.2% | Oct 10, 2025 | Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 befo... |
| CVE-2025-8093 | HIGH | 8.8 | 0.3% | Oct 10, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati... |
| CVE-2025-62162 | HIGH | 7.5 | 0.3% | Oct 10, 2025 | cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.... |
| CVE-2025-62159 | HIGH | 8.7 | 0.3% | Oct 10, 2025 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2025-52885 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulne... |
| CVE-2025-52647 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Head... |
| CVE-2025-11626 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service |
| CVE-2025-61912 | MEDIUM | 5.3 | 0.4% | Oct 10, 2025 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn... |
| CVE-2025-61911 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the san... |
| CVE-2025-11589 | HIGH | 8.8 | 0.3% | Oct 10, 2025 | A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ... |
| CVE-2025-11588 | HIGH | 8.8 | 0.3% | Oct 10, 2025 | A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /cus... |
| CVE-2025-11586 | CRITICAL | 9.8 | 0.8% | Oct 10, 2025 | A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgr... |
| CVE-2025-11585 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now