2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11957 | CRITICAL | 9 | 0.3% | Oct 22, 2025 | Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenti... |
| CVE-2025-62025 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a ... |
| CVE-2025-62023 | CRITICAL | 9 | — | Oct 22, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue... |
| CVE-2025-60238 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue... |
| CVE-2025-60232 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Objec... |
| CVE-2025-60226 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows Object Injection.This iss... |
| CVE-2025-60225 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue... |
| CVE-2025-60224 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object I... |
| CVE-2025-60221 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Object Injec... |
| CVE-2025-60220 | CRITICAL | 9.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects... |
| CVE-2025-60216 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object Injection.This issue affects... |
| CVE-2025-60214 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue... |
| CVE-2025-60213 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affect... |
| CVE-2025-60210 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-lis... |
| CVE-2025-60209 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-fo... |
| CVE-2025-60206 | CRITICAL | 10 | 0.5% | Oct 22, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injectio... |
| CVE-2025-60039 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa:... |
| CVE-2025-59557 | CRITICAL | 9.3 | 0.3% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts A... |
| CVE-2025-59007 | CRITICAL | 9.8 | 0.4% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-gri... |
| CVE-2025-58963 | CRITICAL | 10 | 0.4% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a W... |
| CVE-2025-57870 | CRITICAL | 10 | 0.5% | Oct 22, 2025 | A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes... |
| CVE-2025-52758 | CRITICAL | 9.1 | 0.4% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicio... |
| CVE-2025-49931 | CRITICAL | 9.3 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSear... |
| CVE-2025-49915 | CRITICAL | 9.3 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al... |
| CVE-2025-49901 | CRITICAL | 9.8 | 0.7% | Oct 22, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-l... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now