2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34067CRITICAL10An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Se...
CVE-2025-34057HIGH8.7An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR...
CVE-2025-27026MEDIUM4.9A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticate...
CVE-2025-46647MEDIUM5.3A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the fo...
CVE-2025-39362MEDIUM6.5Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue...
CVE-2025-4946HIGH8.1The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th...
CVE-2025-2330MEDIUM5.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-27025HIGH8.8The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is g...
CVE-2025-27024MEDIUM6.5Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users ...
CVE-2025-27023MEDIUM6.5Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users...
CVE-2025-27022MEDIUM6.5A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated u...
CVE-2025-27021HIGH7.8The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low pri...
CVE-2025-24335LOW2Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, wh...
CVE-2025-24334LOW3.3The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release vers...
CVE-2025-24333MEDIUM6.4Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, whi...
CVE-2025-24332HIGH7.1Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after perfo...
CVE-2025-24331MEDIUM6.4The Single RAN baseband OAM service is intended to run as an unprivileged service. However, it initially starts with roo...
CVE-2025-24330MEDIUM6.4Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radi...
CVE-2025-24329MEDIUM6.4Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Rad...
CVE-2025-24328MEDIUM4.2Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (R...
CVE-2025-6017MEDIUM5.5A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2...
CVE-2025-6464HIGH8.8The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object...
CVE-2025-6463HIGH8.8The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary ...
CVE-2025-52463LOW3.1Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerab...
CVE-2025-52462MEDIUM6.1Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerabi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now