2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52649MEDIUM5.3HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers ...
CVE-2025-52646MEDIUM5.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52645MEDIUM5.3HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut...
CVE-2025-52644HIGH8.2HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of ...
CVE-2025-52643HIGH7.8HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isola...
CVE-2025-52642MEDIUM6.5HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or ...
CVE-2025-52636HIGH7.5HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of...
CVE-2025-2274MEDIUM6.1Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Store...
CVE-2025-71264MEDIUM5.3Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
CVE-2025-6969MEDIUM5.5in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2025-69246CRITICAL9.8Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa...
CVE-2025-69245MEDIUM6.1Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malici...
CVE-2025-69243MEDIUM5.3Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta...
CVE-2025-69242MEDIUM6.1Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, ...
CVE-2025-69241MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authentic...
CVE-2025-69240HIGH8.8Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker ...
CVE-2025-69239LOW2.7Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker...
CVE-2025-69238MEDIUM4.3Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, wh...
CVE-2025-69237MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated ...
CVE-2025-69236MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated a...
CVE-2025-54920HIGH8.8This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ...
CVE-2025-52648CRITICAL9.8HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ...
CVE-2025-52638HIGH7.2HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn...
CVE-2025-52637HIGH7.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52458HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now