2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52649 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers ... |
| CVE-2025-52646 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu... |
| CVE-2025-52645 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut... |
| CVE-2025-52644 | HIGH | 8.2 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ... |
| CVE-2025-52643 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola... |
| CVE-2025-52642 | MEDIUM | 6.5 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or ... |
| CVE-2025-52636 | HIGH | 7.5 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of... |
| CVE-2025-2274 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Store... |
| CVE-2025-71264 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash). |
| CVE-2025-6969 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-69246 | CRITICAL | 9.8 | 0.4% | Mar 16, 2026 | Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa... |
| CVE-2025-69245 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malici... |
| CVE-2025-69243 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta... |
| CVE-2025-69242 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, ... |
| CVE-2025-69241 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authentic... |
| CVE-2025-69240 | HIGH | 8.8 | 0.1% | Mar 16, 2026 | Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ... |
| CVE-2025-69239 | LOW | 2.7 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker... |
| CVE-2025-69238 | MEDIUM | 4.3 | 0.1% | Mar 16, 2026 | Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, wh... |
| CVE-2025-69237 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated ... |
| CVE-2025-69236 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated a... |
| CVE-2025-54920 | HIGH | 8.8 | 5.3% | Mar 16, 2026 | This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ... |
| CVE-2025-52648 | CRITICAL | 9.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ... |
| CVE-2025-52638 | HIGH | 7.2 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn... |
| CVE-2025-52637 | HIGH | 7.3 | 0.2% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu... |
| CVE-2025-52458 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now