2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10850 | CRITICAL | 9.8 | 0.6% | Oct 16, 2025 | The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.... |
| CVE-2025-10742 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin... |
| CVE-2025-11832 | CRITICAL | 9.8 | 0.3% | Oct 15, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech... |
| CVE-2025-62410 | CRITICAL | 9.4 | 0.3% | Oct 15, 2025 | In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating unt... |
| CVE-2025-56749 | CRITICAL | 9.4 | 0.5% | Oct 15, 2025 | Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictabl... |
| CVE-2025-53521 | CRITICAL | 9.8 | 2.2% | Oct 15, 2025 | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex... |
| CVE-2025-55081 | CRITICAL | 9.1 | 0.3% | Oct 15, 2025 | In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was... |
| CVE-2025-9967 | CRITICAL | 9.8 | 0.4% | Oct 15, 2025 | The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve... |
| CVE-2025-10294 | CRITICAL | 9.8 | 0.8% | Oct 15, 2025 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl... |
| CVE-2025-10041 | CRITICAL | 9.8 | 0.9% | Oct 15, 2025 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-39975 | CRITICAL | 9.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp... |
| CVE-2025-62376 | CRITICAL | 9.5 | 0.6% | Oct 14, 2025 | pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cf... |
| CVE-2025-49553 | CRITICAL | 9.3 | 0.5% | Oct 14, 2025 | Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could ... |
| CVE-2025-34267 | CRITICAL | 9.9 | 6.1% | Oct 14, 2025 | Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec... |
| CVE-2025-11736 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit... |
| CVE-2025-59287 | CRITICAL | 9.8 | 100.0% | Oct 14, 2025 | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over ... |
| CVE-2025-55315 | CRITICAL | 9.9 | 66.3% | Oct 14, 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at... |
| CVE-2025-49708 | CRITICAL | 9.9 | 1.1% | Oct 14, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-11548 | CRITICAL | 9.3 | 0.5% | Oct 14, 2025 | A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the a... |
| CVE-2025-49201 | CRITICAL | 9.8 | 0.6% | Oct 14, 2025 | A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions,... |
| CVE-2025-9064 | CRITICAL | 9.1 | 0.6% | Oct 14, 2025 | A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on th... |
| CVE-2025-9063 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exp... |
| CVE-2025-7328 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut... |
| CVE-2025-11721 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presu... |
| CVE-2025-11719 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now