2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-38092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_...
CVE-2025-45029MEDIUM6.5WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cg...
CVE-2025-27026MEDIUM4.9A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticate...
CVE-2025-46647MEDIUM5.3A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the fo...
CVE-2025-39362MEDIUM6.5Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue...
CVE-2025-2330MEDIUM5.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-27024MEDIUM6.5Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users ...
CVE-2025-27023MEDIUM6.5Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users...
CVE-2025-27022MEDIUM6.5A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated u...
CVE-2025-24333MEDIUM6.4Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, whi...
CVE-2025-24331MEDIUM6.4The Single RAN baseband OAM service is intended to run as an unprivileged service. However, it initially starts with roo...
CVE-2025-24330MEDIUM6.4Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radi...
CVE-2025-24329MEDIUM6.4Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Rad...
CVE-2025-24328MEDIUM4.2Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (R...
CVE-2025-6017MEDIUM5.5A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2...
CVE-2025-52462MEDIUM6.1Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerabi...
CVE-2025-6687MEDIUM5.4The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic...
CVE-2025-6686MEDIUM5.4The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic...
CVE-2025-52925MEDIUM5In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka S...
CVE-2025-5692MEDIUM4.3The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capabili...
CVE-2025-6600MEDIUM4.3An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attack...
CVE-2025-48379MEDIUM5.5Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a ...
CVE-2025-46259MEDIUM5.4Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrect...
CVE-2025-27153MEDIUM6.5Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper acces...
CVE-2025-53103MEDIUM5.8JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now