2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27082 | HIGH | 7.2 | 0.4% | Apr 8, 2025 | Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Control... |
| CVE-2025-25227 | HIGH | 7.5 | 0.3% | Apr 8, 2025 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2025-3289 | HIGH | 7.8 | 0.3% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflo... |
| CVE-2025-3288 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read o... |
| CVE-2025-3287 | HIGH | 7.8 | 0.3% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflo... |
| CVE-2025-3286 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read o... |
| CVE-2025-3285 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read o... |
| CVE-2025-32018 | HIGH | 8 | 0.3% | Apr 8, 2025 | Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a re... |
| CVE-2025-32017 | HIGH | 8.8 | 0.5% | Apr 8, 2025 | Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able... |
| CVE-2025-2829 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write ... |
| CVE-2025-2293 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write ... |
| CVE-2025-2288 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write ... |
| CVE-2025-2287 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw... |
| CVE-2025-2286 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw... |
| CVE-2025-2285 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw... |
| CVE-2025-1095 | HIGH | 7.8 | 0.1% | Apr 8, 2025 | IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE)... |
| CVE-2025-32406 | HIGH | 8.6 | 0.5% | Apr 8, 2025 | An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows rem... |
| CVE-2025-22461 | HIGH | 7.2 | 1.1% | Apr 8, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticate... |
| CVE-2025-22458 | HIGH | 7.8 | 0.4% | Apr 8, 2025 | DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated atta... |
| CVE-2025-31498 | HIGH | 8.3 | 0.5% | Apr 8, 2025 | c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when... |
| CVE-2025-30151 | HIGH | 7.5 | 0.3% | Apr 8, 2025 | Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in... |
| CVE-2025-25254 | HIGH | 7.2 | 0.6% | Apr 8, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb ver... |
| CVE-2025-2876 | HIGH | 8.2 | 0.3% | Apr 8, 2025 | The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized lo... |
| CVE-2025-29986 | HIGH | 8.3 | 0.2% | Apr 8, 2025 | Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intend... |
| CVE-2025-2807 | HIGH | 8.8 | 0.7% | Apr 8, 2025 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now