2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38237 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait... |
| CVE-2025-6743 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attrib... |
| CVE-2025-42956 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link wh... |
| CVE-2025-41665 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect de... |
| CVE-2025-24004 | MEDIUM | 5.2 | 0.2% | Jul 8, 2025 | A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsec... |
| CVE-2025-24002 | MEDIUM | 5.3 | 0.4% | Jul 8, 2025 | An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German C... |
| CVE-2025-5957 | MEDIUM | 5.3 | 0.3% | Jul 8, 2025 | The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthor... |
| CVE-2025-5537 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2025-6244 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Store... |
| CVE-2025-5570 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' para... |
| CVE-2025-20695 | MEDIUM | 6.5 | 0.2% | Jul 8, 2025 | In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv... |
| CVE-2025-20694 | MEDIUM | 6.5 | 0.2% | Jul 8, 2025 | In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of serv... |
| CVE-2025-20693 | MEDIUM | 6.5 | 0.1% | Jul 8, 2025 | In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-20692 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20691 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20690 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20689 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20688 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inf... |
| CVE-2025-20687 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local d... |
| CVE-2025-7156 | MEDIUM | 6.3 | 0.2% | Jul 8, 2025 | A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the funct... |
| CVE-2025-43001 | MEDIUM | 6.9 | 0.1% | Jul 8, 2025 | SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directori... |
| CVE-2025-42992 | MEDIUM | 6.9 | 0.1% | Jul 8, 2025 | SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable ... |
| CVE-2025-42986 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privi... |
| CVE-2025-42985 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malic... |
| CVE-2025-42981 | MEDIUM | 6.1 | 0.2% | Jul 8, 2025 | Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now