2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-25269HIGH8.4An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc...
CVE-2025-25268HIGH8.8An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting ...
CVE-2025-24006HIGH7.8A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges...
CVE-2025-24005HIGH7.8A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t...
CVE-2025-24003HIGH8.2An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying ...
CVE-2025-7327HIGH8.8The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2025-7163HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unk...
CVE-2025-7162HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue af...
CVE-2025-7161HIGH8.8A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unk...
CVE-2025-7159HIGH8.8A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue...
CVE-2025-7158HIGH8.8A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vu...
CVE-2025-20686HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-20685HIGH8.8In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (...
CVE-2025-7146HIGH8.7The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a...
CVE-2025-7154HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B...
CVE-2025-42959HIGH8.1An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extract...
CVE-2025-42953HIGH8.1SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting ...
CVE-2025-42952HIGH7.7SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta...
CVE-2025-7152HIGH8.8A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unk...
CVE-2025-7151HIGH8.8A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affe...
CVE-2025-7150HIGH8.8A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnera...
CVE-2025-7149HIGH8.8A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affec...
CVE-2025-53540HIGH8.7arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Se...
CVE-2025-53539HIGH7.5FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr...
CVE-2025-7138HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now