2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-37127HIGH7.2A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authe...
CVE-2025-37126HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote...
CVE-2025-37125HIGH7.5A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation coul...
CVE-2025-37124HIGH8.6A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass fir...
CVE-2025-37123HIGH8.8A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authent...
CVE-2025-56264HIGH7.5The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.
CVE-2025-56263HIGH8.8by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbi...
CVE-2025-34187HIGH8.8Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless...
CVE-2025-34185HIGH7.5Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log...
CVE-2025-34183HIGH7.5Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows u...
CVE-2025-57625HIGH8.8CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user c...
CVE-2025-57624HIGH7.8A DLL hijacking vulnerability in CYRISMA Agent before 444 allows local users to escalate privileges and execute arbitrar...
CVE-2025-56562HIGH7.5An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only...
CVE-2025-54262HIGH7.8Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...
CVE-2025-59334HIGH8.8Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not v...
CVE-2025-59050HIGH7.8Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled d...
CVE-2025-43801HIGH7.5Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppo...
CVE-2025-8894HIGH7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerabi...
CVE-2025-8893HIGH7.8A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab...
CVE-2025-59333HIGH8.1The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-s...
CVE-2025-56295HIGH7.3code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by upload...
CVE-2025-4953HIGH7.4A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman...
CVE-2025-52044HIGH7.5In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, w...
CVE-2025-44034HIGH8SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph par...
CVE-2025-39836HIGH7.8In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now