2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-28381HIGH7.5A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables...
CVE-2025-49468HIGH8.6A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability al...
CVE-2025-39240HIGH7.2Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input ...
CVE-2025-22239HIGH8.1Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to se...
CVE-2025-22236HIGH8.1Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to ...
CVE-2025-5282HIGH7.5The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized l...
CVE-2025-5491HIGH8.8Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a cu...
CVE-2025-47959HIGH7.1Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize...
CVE-2025-30399HIGH7.5Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2025-4232HIGH8.8An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™...
CVE-2025-4231HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform ...
CVE-2025-4230HIGH8.4A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2025-27689HIGH7.8Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged at...
CVE-2025-6031HIGH7.7Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer act...
CVE-2025-5485HIGH8.8User names used to access the web management interface are limited to the device identifier, which is a numerical ident...
CVE-2025-5484HIGH8.3A username and password are required to authenticate to the central SinoTrack device management interface. The username...
CVE-2025-44019HIGH7.1AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated...
CVE-2025-36539HIGH7.1AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticate...
CVE-2025-43866HIGH7.5vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is ...
CVE-2025-5982HIGH7.5An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18....
CVE-2025-49080HIGH7.5There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with networ...
CVE-2025-46035HIGH7.5Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the o...
CVE-2025-49200HIGH7.5The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downl...
CVE-2025-49198HIGH7.5The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of...
CVE-2025-49197HIGH7.5The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now