2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60206 | CRITICAL | 10 | 0.5% | Oct 22, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injectio... |
| CVE-2025-60039 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa:... |
| CVE-2025-59557 | CRITICAL | 9.3 | 0.3% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts A... |
| CVE-2025-59007 | CRITICAL | 9.8 | 0.4% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-gri... |
| CVE-2025-58963 | CRITICAL | 10 | 0.4% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a W... |
| CVE-2025-57870 | CRITICAL | 10 | 0.5% | Oct 22, 2025 | A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes... |
| CVE-2025-52758 | CRITICAL | 9.1 | 0.4% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicio... |
| CVE-2025-49931 | CRITICAL | 9.3 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSear... |
| CVE-2025-49915 | CRITICAL | 9.3 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al... |
| CVE-2025-49901 | CRITICAL | 9.8 | 0.7% | Oct 22, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-l... |
| CVE-2025-49380 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder ... |
| CVE-2025-49060 | CRITICAL | 10 | 0.4% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell ... |
| CVE-2025-48106 | CRITICAL | 10 | 0.6% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious F... |
| CVE-2025-56447 | CRITICAL | 9.8 | 0.3% | Oct 22, 2025 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. |
| CVE-2025-41108 | CRITICAL | 9.8 | 0.3% | Oct 22, 2025 | The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to t... |
| CVE-2025-41723 | CRITICAL | 9.8 | 1.2% | Oct 22, 2025 | The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the ... |
| CVE-2025-62481 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support... |
| CVE-2025-61757 | CRITICAL | 9.8 | 88.3% | Oct 21, 2025 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers... |
| CVE-2025-53072 | CRITICAL | 9.8 | 0.7% | Oct 21, 2025 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support... |
| CVE-2025-53037 | CRITICAL | 9.8 | 0.4% | Oct 21, 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2025-60772 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthen... |
| CVE-2025-11534 | CRITICAL | 9.3 | 0.8% | Oct 21, 2025 | The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al... |
| CVE-2025-11625 | CRITICAL | 9.8 | 0.4% | Oct 21, 2025 | Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypa... |
| CVE-2025-11624 | CRITICAL | 9.8 | 0.3% | Oct 21, 2025 | Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger... |
| CVE-2025-10640 | CRITICAL | 9.8 | 0.9% | Oct 21, 2025 | An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now