2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38092 | MEDIUM | 5.5 | 0.1% | Jul 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_... |
| CVE-2025-45029 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cg... |
| CVE-2025-27026 | MEDIUM | 4.9 | 0.3% | Jul 2, 2025 | A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticate... |
| CVE-2025-46647 | MEDIUM | 5.3 | 0.4% | Jul 2, 2025 | A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the fo... |
| CVE-2025-39362 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue... |
| CVE-2025-2330 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-27024 | MEDIUM | 6.5 | 0.3% | Jul 2, 2025 | Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users ... |
| CVE-2025-27023 | MEDIUM | 6.5 | 0.5% | Jul 2, 2025 | Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users... |
| CVE-2025-27022 | MEDIUM | 6.5 | 0.5% | Jul 2, 2025 | A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated u... |
| CVE-2025-24333 | MEDIUM | 6.4 | 0.2% | Jul 2, 2025 | Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, whi... |
| CVE-2025-24331 | MEDIUM | 6.4 | 0.1% | Jul 2, 2025 | The Single RAN baseband OAM service is intended to run as an unprivileged service. However, it initially starts with roo... |
| CVE-2025-24330 | MEDIUM | 6.4 | 0.2% | Jul 2, 2025 | Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radi... |
| CVE-2025-24329 | MEDIUM | 6.4 | 0.2% | Jul 2, 2025 | Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Rad... |
| CVE-2025-24328 | MEDIUM | 4.2 | 0.2% | Jul 2, 2025 | Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (R... |
| CVE-2025-6017 | MEDIUM | 5.5 | 0.1% | Jul 2, 2025 | A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2... |
| CVE-2025-52462 | MEDIUM | 6.1 | 0.2% | Jul 2, 2025 | Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerabi... |
| CVE-2025-6687 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic... |
| CVE-2025-6686 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic... |
| CVE-2025-52925 | MEDIUM | 5 | 0.1% | Jul 2, 2025 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S... |
| CVE-2025-5692 | MEDIUM | 4.3 | 0.2% | Jul 2, 2025 | The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili... |
| CVE-2025-6600 | MEDIUM | 4.3 | 0.3% | Jul 1, 2025 | An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attack... |
| CVE-2025-48379 | MEDIUM | 5.5 | 0.3% | Jul 1, 2025 | Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a ... |
| CVE-2025-46259 | MEDIUM | 5.4 | 0.3% | Jul 1, 2025 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrect... |
| CVE-2025-27153 | MEDIUM | 6.5 | 0.2% | Jul 1, 2025 | Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper acces... |
| CVE-2025-53103 | MEDIUM | 5.8 | 0.1% | Jul 1, 2025 | JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now