2025 CVE Vulnerabilities

45,260 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7169CRITICAL9.8A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknow...
CVE-2025-7168CRITICAL9.8A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects...
CVE-2025-38237MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait...
CVE-2025-38236HIGH7.8In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs....
CVE-2025-7346HIGH8.7Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create ...
CVE-2025-7167HIGH8.8A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerabilit...
CVE-2025-7166HIGH8.8A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an...
CVE-2025-6746HIGH8.8The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via ...
CVE-2025-6743MEDIUM5.4The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attrib...
CVE-2025-42956MEDIUM6.1SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link wh...
CVE-2025-41668HIGH8.8A low privileged remote attacker with file access can replace a critical file or folder used by the service security-pro...
CVE-2025-41667HIGH8.8A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read...
CVE-2025-41666HIGH8.8A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write an...
CVE-2025-41665MEDIUM6.5An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de...
CVE-2025-25271HIGH8.8An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configura...
CVE-2025-25270CRITICAL9.8An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with...
CVE-2025-25269HIGH8.4An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc...
CVE-2025-25268HIGH8.8An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting ...
CVE-2025-24006HIGH7.8A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges...
CVE-2025-24005HIGH7.8A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t...
CVE-2025-24004MEDIUM5.2A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsec...
CVE-2025-24003HIGH8.2An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying ...
CVE-2025-24002MEDIUM5.3An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German C...
CVE-2025-7327HIGH8.8The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2025-7165CRITICAL9.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now