2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52644HIGH8.2HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ...
CVE-2025-52643HIGH7.8HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola...
CVE-2025-52636HIGH7.5HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of...
CVE-2025-69240HIGH8.8Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ...
CVE-2025-54920HIGH8.8This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ...
CVE-2025-52638HIGH7.2HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn...
CVE-2025-52637HIGH7.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52458HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-41432HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-25277HIGH7in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2025-15587HIGH8.6Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini...
CVE-2025-15554HIGH7.8Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstat...
CVE-2025-15553HIGH7.1Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati...
CVE-2025-15552HIGH7.8Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio...
CVE-2025-15540HIGH8.8"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due t...
CVE-2025-14287HIGH8.8A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/...
CVE-2025-11500HIGH8.7Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -...
CVE-2025-10685HIGH7.7Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs...
CVE-2025-71263HIGH7.8In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h...
CVE-2025-36368HIGH7.2IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2....
CVE-2025-13779HIGH8.3Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW...
CVE-2025-13778HIGH7.1Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW...
CVE-2025-13777HIGH8.3Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW...
CVE-2025-13726HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke...
CVE-2025-13723HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now