2025 CVE Vulnerabilities
45,260 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7169 | CRITICAL | 9.8 | 0.4% | Jul 8, 2025 | A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknow... |
| CVE-2025-7168 | CRITICAL | 9.8 | 0.4% | Jul 8, 2025 | A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects... |
| CVE-2025-38237 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait... |
| CVE-2025-38236 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs.... |
| CVE-2025-7346 | HIGH | 8.7 | 0.3% | Jul 8, 2025 | Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create ... |
| CVE-2025-7167 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerabilit... |
| CVE-2025-7166 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an... |
| CVE-2025-6746 | HIGH | 8.8 | 0.5% | Jul 8, 2025 | The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via ... |
| CVE-2025-6743 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attrib... |
| CVE-2025-42956 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link wh... |
| CVE-2025-41668 | HIGH | 8.8 | 0.5% | Jul 8, 2025 | A low privileged remote attacker with file access can replace a critical file or folder used by the service security-pro... |
| CVE-2025-41667 | HIGH | 8.8 | 0.5% | Jul 8, 2025 | A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read... |
| CVE-2025-41666 | HIGH | 8.8 | 0.5% | Jul 8, 2025 | A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write an... |
| CVE-2025-41665 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de... |
| CVE-2025-25271 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configura... |
| CVE-2025-25270 | CRITICAL | 9.8 | 0.6% | Jul 8, 2025 | An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with... |
| CVE-2025-25269 | HIGH | 8.4 | 0.2% | Jul 8, 2025 | An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc... |
| CVE-2025-25268 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting ... |
| CVE-2025-24006 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges... |
| CVE-2025-24005 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t... |
| CVE-2025-24004 | MEDIUM | 5.2 | 0.2% | Jul 8, 2025 | A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsec... |
| CVE-2025-24003 | HIGH | 8.2 | 0.3% | Jul 8, 2025 | An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying ... |
| CVE-2025-24002 | MEDIUM | 5.3 | 0.4% | Jul 8, 2025 | An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German C... |
| CVE-2025-7327 | HIGH | 8.8 | 0.8% | Jul 8, 2025 | The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... |
| CVE-2025-7165 | CRITICAL | 9.8 | 0.5% | Jul 8, 2025 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now