2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69236MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated a...
CVE-2025-54920HIGH8.8This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ...
CVE-2025-52648CRITICAL9.8HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ...
CVE-2025-52638HIGH7.2HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn...
CVE-2025-52637HIGH7.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52458HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-41432HIGH7.8in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2025-26474LOW3.3in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can...
CVE-2025-25277HIGH7in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2025-15587HIGH8.6Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini...
CVE-2025-15554HIGH7.8Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstat...
CVE-2025-15553HIGH7.1Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati...
CVE-2025-15552HIGH7.8Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio...
CVE-2025-15540HIGH8.8"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due t...
CVE-2025-15060CRITICAL9.8claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2025-14287HIGH8.8A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/...
CVE-2025-13460MEDIUM5.3IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response disc...
CVE-2025-13459MEDIUM4.9IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc...
CVE-2025-13212MEDIUM4.3IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email servi...
CVE-2025-12736MEDIUM6.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial...
CVE-2025-11500HIGH8.7Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -...
CVE-2025-10685HIGH7.7Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs...
CVE-2025-10461MEDIUM5.3Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker ...
CVE-2025-8766MEDIUM6.4A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from...
CVE-2025-71263HIGH7.8In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now