2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26677HIGH7.5Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over...
CVE-2025-24063HIGH7.8Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-21264HIGH7.1Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a se...
CVE-2025-0035HIGH7.3Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potential...
CVE-2025-4428HIGH8.8Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms all...
CVE-2025-4427HIGH7.5An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to a...
CVE-2025-47276HIGH7.5Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating syste...
CVE-2025-30207HIGH7.5Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff...
CVE-2025-28055HIGH7.5upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit
CVE-2025-28057HIGH7.2owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.
CVE-2025-22460HIGH7.8Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to e...
CVE-2025-32917HIGH8.8Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p...
CVE-2025-4646HIGH7.2Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This...
CVE-2025-40582HIGH8.5A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed...
CVE-2025-40581HIGH8.4A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed...
CVE-2025-40580HIGH7.8A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40579HIGH7.8A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40574HIGH8.5A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices...
CVE-2025-40556HIGH7.1A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet AT...
CVE-2025-32454HIGH7.8A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualizat...
CVE-2025-31930HIGH8.8A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph ...
CVE-2025-30176HIGH8.7A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC N...
CVE-2025-30175HIGH8.7A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC N...
CVE-2025-30174HIGH8.7A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC N...
CVE-2025-24510HIGH7.1A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle spec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now