2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40943CRITICAL9.6Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug...
CVE-2025-27769LOW2.6A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC...
CVE-2025-13957HIGH7.5CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code exec...
CVE-2025-13902MEDIUM5.4CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that co...
CVE-2025-13901MEDIUM5.3CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine...
CVE-2025-11739HIGH7.8CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr...
CVE-2025-36173MEDIUM6.1Affected Product(s)Version(s)InfoSphere Data Architect9.2.1
CVE-2025-36105MEDIUM4.4IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s...
CVE-2025-2399MEDIUM5.9Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri...
CVE-2025-11158CRITICAL9.1Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric...
CVE-2025-70973MEDIUM4.8ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated...
CVE-2025-70028HIGH7.5An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov...
CVE-2025-15603Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...
CVE-2025-70031HIGH8.8An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70030HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd...
CVE-2025-68402HIGH8.2FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c...
CVE-2025-62166HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication...
CVE-2025-70032MEDIUM6.1An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70039CRITICAL9.8An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag...
CVE-2025-70038HIGH8.8An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw...
CVE-2025-70034HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.
CVE-2025-70033MEDIUM5.4An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed ...
CVE-2025-70037MEDIUM6.1An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This a...
CVE-2025-15568HIGH8A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a...
CVE-2025-70060MEDIUM5.4An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now