2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25269 | HIGH | 8.4 | 0.2% | Jul 8, 2025 | An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc... |
| CVE-2025-25268 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting ... |
| CVE-2025-24006 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges... |
| CVE-2025-24005 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t... |
| CVE-2025-24003 | HIGH | 8.2 | 0.3% | Jul 8, 2025 | An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying ... |
| CVE-2025-7327 | HIGH | 8.8 | 0.8% | Jul 8, 2025 | The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... |
| CVE-2025-7163 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unk... |
| CVE-2025-7162 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue af... |
| CVE-2025-7161 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unk... |
| CVE-2025-7159 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue... |
| CVE-2025-7158 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vu... |
| CVE-2025-20686 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-20685 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-7146 | HIGH | 8.7 | 0.5% | Jul 8, 2025 | The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a... |
| CVE-2025-7154 | HIGH | 8.8 | 2.6% | Jul 8, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B... |
| CVE-2025-42959 | HIGH | 8.1 | 0.5% | Jul 8, 2025 | An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extract... |
| CVE-2025-42953 | HIGH | 8.1 | 0.4% | Jul 8, 2025 | SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting ... |
| CVE-2025-42952 | HIGH | 7.7 | 0.4% | Jul 8, 2025 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta... |
| CVE-2025-7152 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unk... |
| CVE-2025-7151 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affe... |
| CVE-2025-7150 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnera... |
| CVE-2025-7149 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affec... |
| CVE-2025-53540 | HIGH | 8.7 | 0.3% | Jul 7, 2025 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Se... |
| CVE-2025-53539 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr... |
| CVE-2025-7138 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now