2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52948HIGH8.2An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Netwo...
CVE-2025-52947HIGH7.1An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specifi...
CVE-2025-52946HIGH8.7A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Ju...
CVE-2025-52089HIGH8.8A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenti...
CVE-2025-48924MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with comm...
CVE-2025-30661HIGH8.5An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Network...
CVE-2025-51591LOW3.7A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole in...
CVE-2025-53862LOW3.5A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw...
CVE-2025-53861LOW3.1A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the...
CVE-2025-6788MEDIUM5.3A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong co...
CVE-2025-50125MEDIUM6.3A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execu...
CVE-2025-50124HIGH7.2A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server...
CVE-2025-50123HIGH7.2A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote comman...
CVE-2025-50122HIGH8.9A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generati...
CVE-2025-50121CRITICAL9.5A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist...
CVE-2025-3933MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-6851MEDIUM6.5The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2025-6838MEDIUM4.1The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0...
CVE-2025-6438MEDIUM5.9A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulati...
CVE-2025-7442HIGH7.5The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters i...
CVE-2025-6745MEDIUM5.3The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via ...
CVE-2025-6068MEDIUM5.4The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...
CVE-2025-5530MEDIUM5.4The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-4593MEDIUM6.5The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2025-6716MEDIUM6.4The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now