2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69783 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust... |
| CVE-2025-52644 | HIGH | 8.2 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ... |
| CVE-2025-52643 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola... |
| CVE-2025-52636 | HIGH | 7.5 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of... |
| CVE-2025-69240 | HIGH | 8.8 | 0.1% | Mar 16, 2026 | Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ... |
| CVE-2025-54920 | HIGH | 8.8 | 5.3% | Mar 16, 2026 | This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ... |
| CVE-2025-52638 | HIGH | 7.2 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn... |
| CVE-2025-52637 | HIGH | 7.3 | 0.2% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu... |
| CVE-2025-52458 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-41432 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-25277 | HIGH | 7 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-15587 | HIGH | 8.6 | 0.2% | Mar 16, 2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini... |
| CVE-2025-15554 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstat... |
| CVE-2025-15553 | HIGH | 7.1 | 0.1% | Mar 16, 2026 | Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati... |
| CVE-2025-15552 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio... |
| CVE-2025-15540 | HIGH | 8.8 | 0.5% | Mar 16, 2026 | "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due t... |
| CVE-2025-14287 | HIGH | 8.8 | 1.5% | Mar 16, 2026 | A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/... |
| CVE-2025-11500 | HIGH | 8.7 | 0.3% | Mar 16, 2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -... |
| CVE-2025-10685 | HIGH | 7.7 | 0.5% | Mar 16, 2026 | Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs... |
| CVE-2025-71263 | HIGH | 7.8 | 0.2% | Mar 13, 2026 | In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h... |
| CVE-2025-36368 | HIGH | 7.2 | 0.3% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.... |
| CVE-2025-13779 | HIGH | 8.3 | 0.3% | Mar 13, 2026 | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW... |
| CVE-2025-13778 | HIGH | 7.1 | 0.3% | Mar 13, 2026 | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW... |
| CVE-2025-13777 | HIGH | 8.3 | 0.2% | Mar 13, 2026 | Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW... |
| CVE-2025-13726 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now