2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0303 | HIGH | 7.8 | 0.2% | Feb 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2025-22880 | HIGH | 7.8 | 0.2% | Feb 7, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2025-0675 | HIGH | 8.7 | 0.5% | Feb 7, 2025 | Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclos... |
| CVE-2025-21408 | HIGH | 8.8 | 1.2% | Feb 6, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21342 | HIGH | 8.8 | 1.1% | Feb 6, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21283 | HIGH | 8.8 | 1.3% | Feb 6, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21279 | HIGH | 8.8 | 1.4% | Feb 6, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21177 | HIGH | 8.8 | 1.2% | Feb 6, 2025 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges o... |
| CVE-2025-23094 | HIGH | 7.3 | 1.3% | Feb 6, 2025 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 t... |
| CVE-2025-23093 | HIGH | 8.8 | 0.5% | Feb 6, 2025 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 co... |
| CVE-2025-24787 | HIGH | 7.5 | 0.5% | Feb 6, 2025 | WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter inject... |
| CVE-2025-23217 | HIGH | 8.2 | 0.8% | Feb 6, 2025 | mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw... |
| CVE-2025-22867 | HIGH | 7.5 | 0.6% | Feb 6, 2025 | On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ... |
| CVE-2025-0994 | HIGH | 8.8 | 27.4% | Feb 6, 2025 | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to... |
| CVE-2025-23236 | HIGH | 8.8 | 0.2% | Feb 6, 2025 | Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs ... |
| CVE-2025-22894 | HIGH | 8.8 | 0.1% | Feb 6, 2025 | Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier... |
| CVE-2025-20094 | HIGH | 8.8 | 0.1% | Feb 6, 2025 | Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier... |
| CVE-2025-22890 | HIGH | 8.8 | 0.2% | Feb 6, 2025 | Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an atta... |
| CVE-2025-24372 | HIGH | 7.3 | 0.4% | Feb 5, 2025 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted f... |
| CVE-2025-24497 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Softw... |
| CVE-2025-24326 | HIGH | 8.9 | 0.4% | Feb 5, 2025 | When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case a... |
| CVE-2025-24320 | HIGH | 8 | 0.4% | Feb 5, 2025 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that... |
| CVE-2025-24312 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server... |
| CVE-2025-23412 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. ... |
| CVE-2025-23239 | HIGH | 8.7 | 0.7% | Feb 5, 2025 | When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vuln... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now