2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27082HIGH7.2Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Control...
CVE-2025-25227HIGH7.5Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2025-3289HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflo...
CVE-2025-3288HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read o...
CVE-2025-3287HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflo...
CVE-2025-3286HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read o...
CVE-2025-3285HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read o...
CVE-2025-32018HIGH8Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a re...
CVE-2025-32017HIGH8.8Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able...
CVE-2025-2829HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write ...
CVE-2025-2293HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write ...
CVE-2025-2288HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write ...
CVE-2025-2287HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw...
CVE-2025-2286HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw...
CVE-2025-2285HIGH7.8A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw...
CVE-2025-1095HIGH7.8IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE)...
CVE-2025-32406HIGH8.6An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows rem...
CVE-2025-22461HIGH7.2SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticate...
CVE-2025-22458HIGH7.8DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated atta...
CVE-2025-31498HIGH8.3c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when...
CVE-2025-30151HIGH7.5Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in...
CVE-2025-25254HIGH7.2An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb ver...
CVE-2025-2876HIGH8.2The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized lo...
CVE-2025-29986HIGH8.3Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intend...
CVE-2025-2807HIGH8.8The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now