2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-69783HIGH7.8A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trust...
CVE-2025-52644HIGH8.2HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ...
CVE-2025-52643HIGH7.8HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola...
CVE-2025-52636HIGH7.5HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of...
CVE-2025-69240HIGH8.8Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ...
CVE-2025-54920HIGH8.8This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ...
CVE-2025-52638HIGH7.2HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn...
CVE-2025-52637HIGH7.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52458HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-41432HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-25277HIGH7in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2025-15587HIGH8.6Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini...
CVE-2025-15554HIGH7.8Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstat...
CVE-2025-15553HIGH7.1Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati...
CVE-2025-15552HIGH7.8Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio...
CVE-2025-15540HIGH8.8"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due t...
CVE-2025-14287HIGH8.8A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/...
CVE-2025-11500HIGH8.7Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -...
CVE-2025-10685HIGH7.7Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs...
CVE-2025-71263HIGH7.8In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h...
CVE-2025-36368HIGH7.2IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2....
CVE-2025-13779HIGH8.3Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW...
CVE-2025-13778HIGH7.1Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW...
CVE-2025-13777HIGH8.3Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW...
CVE-2025-13726HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now