2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24009HIGH8.2A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2...
CVE-2025-24008HIGH8.7A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2...
CVE-2025-24007HIGH8.7A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2...
CVE-2025-22248HIGH7.5The bitnami/pgpool Docker image, and the bitnami/postgres-ha k8s chart, under default configurations, comes with an 'rep...
CVE-2025-41645HIGH8.6An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that ac...
CVE-2025-27696HIGH8.8Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by ...
CVE-2025-4474HIGH8.8The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t...
CVE-2025-4473HIGH8.8The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t...
CVE-2025-4317HIGH8.8The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem...
CVE-2025-22249HIGH8.2VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this...
CVE-2025-22246HIGH7.5Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
CVE-2025-4396HIGH7.5The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags qu...
CVE-2025-35471HIGH7.8conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR...
CVE-2025-43011HIGH7.7Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization c...
CVE-2025-43010HIGH8.3SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP ...
CVE-2025-43000HIGH7.9Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwis...
CVE-2025-30018HIGH7.5The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an a...
CVE-2025-31259HIGH7.8A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS...
CVE-2025-31253HIGH7.1This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. Muting the ...
CVE-2025-31249HIGH7.1A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to acces...
CVE-2025-31247HIGH7.5A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7...
CVE-2025-31246HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. C...
CVE-2025-31244HIGH8.8A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be ...
CVE-2025-31240HIGH7.5This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ven...
CVE-2025-31238HIGH7.3The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now