2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59944 | CRITICAL | 9.8 | 0.3% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the wa... |
| CVE-2025-59943 | CRITICAL | 9.8 | 0.4% | Oct 3, 2025 | phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e... |
| CVE-2025-49844 | CRITICAL | 9.9 | 86.3% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-10729 | CRITICAL | 9.4 | 0.2% | Oct 3, 2025 | The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creatio... |
| CVE-2025-10728 | CRITICAL | 9.4 | 0.2% | Oct 3, 2025 | When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading t... |
| CVE-2025-9286 | CRITICAL | 9.8 | 0.4% | Oct 3, 2025 | The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authoriza... |
| CVE-2025-9209 | CRITICAL | 9.8 | 2.2% | Oct 3, 2025 | The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.... |
| CVE-2025-7721 | CRITICAL | 9.8 | 0.6% | Oct 3, 2025 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Incl... |
| CVE-2025-40636 | CRITICAL | 9.3 | 0.3% | Oct 3, 2025 | SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retri... |
| CVE-2025-10726 | CRITICAL | 9.1 | 0.4% | Oct 3, 2025 | The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a... |
| CVE-2025-10547 | CRITICAL | 9.8 | 0.6% | Oct 3, 2025 | An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all... |
| CVE-2025-6388 | CRITICAL | 9.8 | 0.5% | Oct 3, 2025 | The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1... |
| CVE-2025-61605 | CRITICAL | 9.8 | 0.4% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL In... |
| CVE-2025-61603 | CRITICAL | 9.8 | 0.4% | Oct 2, 2025 | WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability whi... |
| CVE-2025-59407 | CRITICAL | 9.8 | 0.5% | Oct 2, 2025 | The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falco... |
| CVE-2025-59403 | CRITICAL | 9.8 | 1.0% | Oct 2, 2025 | The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authenticat... |
| CVE-2025-59743 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u... |
| CVE-2025-59742 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u... |
| CVE-2025-59741 | CRITICAL | 9.8 | 1.3% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59740 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59739 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59738 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59737 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59736 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59735 | CRITICAL | 9.8 | 1.5% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now