2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-0303HIGH7.8in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2025-22880HIGH7.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2025-0675HIGH8.7Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclos...
CVE-2025-21408HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21342HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21283HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21279HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21177HIGH8.8Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges o...
CVE-2025-23094HIGH7.3The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 t...
CVE-2025-23093HIGH8.8The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 co...
CVE-2025-24787HIGH7.5WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter inject...
CVE-2025-23217HIGH8.2mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw...
CVE-2025-22867HIGH7.5On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ...
CVE-2025-0994HIGH8.8Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to...
CVE-2025-23236HIGH8.8Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs ...
CVE-2025-22894HIGH8.8Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier...
CVE-2025-20094HIGH8.8Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier...
CVE-2025-22890HIGH8.8Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an atta...
CVE-2025-24372HIGH7.3CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted f...
CVE-2025-24497HIGH8.7When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Softw...
CVE-2025-24326HIGH8.9When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case a...
CVE-2025-24320HIGH8A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that...
CVE-2025-24312HIGH8.7When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server...
CVE-2025-23412HIGH8.7When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. ...
CVE-2025-23239HIGH8.7When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now