2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-43585HIGH8.2Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authori...
CVE-2025-40591HIGH8.3A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40567HIGH7.1A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532...
CVE-2025-5353HIGH7.8A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt s...
CVE-2025-5335HIGH7.8A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a...
CVE-2025-46612HIGH7.2The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary comma...
CVE-2025-37100HIGH7.7A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to un...
CVE-2025-30145HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be ...
CVE-2025-22463HIGH7.3A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt t...
CVE-2025-22455HIGH7.8A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt st...
CVE-2025-49511HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery...
CVE-2025-49454HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-43701HIGH7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settin...
CVE-2025-43700HIGH7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted dat...
CVE-2025-43697HIGH7.5Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted da...
CVE-2025-40662HIGH7.5Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents...
CVE-2025-40661HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40660HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40659HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-40658HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows...
CVE-2025-5743HIGH7CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-5740HIGH8.6CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-4681HIGH8.6Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abu...
CVE-2025-4680HIGH8.6Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorr...
CVE-2025-3898HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated maliciou...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now