2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41432HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-26474LOW3.3in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can...
CVE-2025-25277HIGH7in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2025-15587HIGH8.6Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini...
CVE-2025-15554HIGH7.8Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstat...
CVE-2025-15553HIGH7.1Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati...
CVE-2025-15552HIGH7.8Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio...
CVE-2025-15540HIGH8.8"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due t...
CVE-2025-15060CRITICAL9.8claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2025-14287HIGH8.8A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/...
CVE-2025-13460MEDIUM5.3IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response disc...
CVE-2025-13459MEDIUM4.9IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc...
CVE-2025-13212MEDIUM4.3IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email servi...
CVE-2025-12736MEDIUM6.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial...
CVE-2025-11500HIGH8.7Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -...
CVE-2025-10685HIGH7.7Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs...
CVE-2025-10461MEDIUM5.3Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker ...
CVE-2025-8766MEDIUM6.4A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from...
CVE-2025-71263HIGH7.8In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h...
CVE-2025-66249MEDIUM6.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue...
CVE-2025-60012MEDIUM6.3Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0...
CVE-2025-57849MEDIUM6.4A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being...
CVE-2025-36368HIGH7.2IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2....
CVE-2025-15515MEDIUM5.5The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific condit...
CVE-2025-14811MEDIUM5.9IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now