2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49380 | CRITICAL | 9.8 | 0.5% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder ... |
| CVE-2025-49060 | CRITICAL | 10 | 0.5% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell ... |
| CVE-2025-48106 | CRITICAL | 10 | 0.6% | Oct 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious F... |
| CVE-2025-56447 | CRITICAL | 9.8 | 0.3% | Oct 22, 2025 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. |
| CVE-2025-41108 | CRITICAL | 9.8 | 0.3% | Oct 22, 2025 | The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to t... |
| CVE-2025-41723 | CRITICAL | 9.8 | 1.2% | Oct 22, 2025 | The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the ... |
| CVE-2025-62481 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support... |
| CVE-2025-61757 | CRITICAL | 9.8 | 88.3% | Oct 21, 2025 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers... |
| CVE-2025-53072 | CRITICAL | 9.8 | 0.7% | Oct 21, 2025 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support... |
| CVE-2025-53037 | CRITICAL | 9.8 | 0.4% | Oct 21, 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2025-60772 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthen... |
| CVE-2025-11534 | CRITICAL | 9.3 | 0.8% | Oct 21, 2025 | The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al... |
| CVE-2025-11625 | CRITICAL | 9.8 | 0.4% | Oct 21, 2025 | Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypa... |
| CVE-2025-11624 | CRITICAL | 9.8 | 0.3% | Oct 21, 2025 | Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger... |
| CVE-2025-10640 | CRITICAL | 9.8 | 0.9% | Oct 21, 2025 | An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side aut... |
| CVE-2025-12004 | CRITICAL | 10 | 0.3% | Oct 21, 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext... |
| CVE-2025-10916 | CRITICAL | 9.1 | 0.3% | Oct 21, 2025 | The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-7851 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |
| CVE-2025-6542 | CRITICAL | 9.8 | 0.9% | Oct 21, 2025 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
| CVE-2025-61303 | CRITICAL | 9.8 | 0.4% | Oct 20, 2025 | Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability... |
| CVE-2025-8053 | CRITICAL | 9.1 | 0.2% | Oct 20, 2025 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-55086 | CRITICAL | 9.8 | 0.4% | Oct 20, 2025 | In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there ... |
| CVE-2025-9574 | CRITICAL | 10 | 0.8% | Oct 20, 2025 | Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects ... |
| CVE-2025-10678 | CRITICAL | 9.3 | 0.4% | Oct 20, 2025 | NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin accoun... |
| CVE-2025-54957 | CRITICAL | 9.8 | 1.6% | Oct 20, 2025 | An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now