2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49143MEDIUM5.9Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by ...
CVE-2025-49142HIGH7.1Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or...
CVE-2025-48937MEDIUM4.9matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 an...
CVE-2025-48879MEDIUM6.5OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to sen...
CVE-2025-48067MEDIUM4.6OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11....
CVE-2025-47110HIGH8.4Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site...
CVE-2025-44044HIGH7.5Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable Sea...
CVE-2025-44043MEDIUM5.4Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common...
CVE-2025-43586HIGH8.1Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ...
CVE-2025-43585HIGH8.2Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authori...
CVE-2025-40591HIGH8.3A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40585CRITICAL9.9A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain...
CVE-2025-40569MEDIUM5.9A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532...
CVE-2025-40568MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532...
CVE-2025-40567HIGH7.1A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532...
CVE-2025-30220CRITICAL9.1GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Ecl...
CVE-2025-27207MEDIUM6.5Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ...
CVE-2025-27206MEDIUM5.3Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ...
CVE-2025-5353HIGH7.8A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt s...
CVE-2025-5335HIGH7.8A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a...
CVE-2025-46612HIGH7.2The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary comma...
CVE-2025-37100HIGH7.7A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to un...
CVE-2025-30145HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be ...
CVE-2025-27505MEDIUM5.3GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the def...
CVE-2025-26395MEDIUM4.3SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitiz...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now