2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38103 | HIGH | 7.1 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: Eliminate recurrent out-of-bounds bug ... |
| CVE-2025-38102 | HIGH | 7 | 0.1% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and v... |
| CVE-2025-38101 | HIGH | 7.8 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix buffer locking in ring_buffer_subb... |
| CVE-2025-43025 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 o... |
| CVE-2025-34079 | HIGH | 7.8 | 1.3% | Jul 2, 2025 | An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and Ex... |
| CVE-2025-34078 | HIGH | 7.8 | 0.5% | Jul 2, 2025 | A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts... |
| CVE-2025-34076 | HIGH | 7.2 | 1.3% | Jul 2, 2025 | An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the ba... |
| CVE-2025-49713 | HIGH | 8.8 | 0.7% | Jul 2, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2025-52841 | HIGH | 8.8 | 0.2% | Jul 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This i... |
| CVE-2025-53110 | HIGH | 7.3 | 0.5% | Jul 2, 2025 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio... |
| CVE-2025-53109 | HIGH | 7.3 | 0.7% | Jul 2, 2025 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio... |
| CVE-2025-38091 | HIGH | 7.8 | 0.1% | Jul 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to g... |
| CVE-2025-53106 | HIGH | 8.8 | 0.5% | Jul 2, 2025 | Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-... |
| CVE-2025-49588 | HIGH | 8.7 | 0.3% | Jul 2, 2025 | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve... |
| CVE-2025-34057 | HIGH | 8.7 | 6.4% | Jul 2, 2025 | An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR... |
| CVE-2025-4946 | HIGH | 8.1 | 0.6% | Jul 2, 2025 | The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th... |
| CVE-2025-27025 | HIGH | 8.8 | 0.6% | Jul 2, 2025 | The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is g... |
| CVE-2025-27021 | HIGH | 7.8 | 0.1% | Jul 2, 2025 | The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low pri... |
| CVE-2025-24332 | HIGH | 7.1 | 0.2% | Jul 2, 2025 | Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after perfo... |
| CVE-2025-6464 | HIGH | 8.8 | 0.5% | Jul 2, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object... |
| CVE-2025-6463 | HIGH | 8.8 | 10.5% | Jul 2, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary ... |
| CVE-2025-6459 | HIGH | 8.8 | 0.2% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Reques... |
| CVE-2025-6437 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2025-5817 | HIGH | 7.2 | 0.2% | Jul 2, 2025 | The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2025-5339 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now