2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69236 | MEDIUM | 5.4 | 0.2% | Mar 16, 2026 | Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated a... |
| CVE-2025-54920 | HIGH | 8.8 | 5.3% | Mar 16, 2026 | This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and ... |
| CVE-2025-52648 | CRITICAL | 9.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ... |
| CVE-2025-52638 | HIGH | 7.2 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn... |
| CVE-2025-52637 | HIGH | 7.3 | 0.2% | Mar 16, 2026 | HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu... |
| CVE-2025-52458 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-41432 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2025-26474 | LOW | 3.3 | 0.1% | Mar 16, 2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can... |
| CVE-2025-25277 | HIGH | 7 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2025-15587 | HIGH | 8.6 | 0.2% | Mar 16, 2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini... |
| CVE-2025-15554 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstat... |
| CVE-2025-15553 | HIGH | 7.1 | 0.1% | Mar 16, 2026 | Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati... |
| CVE-2025-15552 | HIGH | 7.8 | 0.1% | Mar 16, 2026 | Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio... |
| CVE-2025-15540 | HIGH | 8.8 | 0.5% | Mar 16, 2026 | "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due t... |
| CVE-2025-15060 | CRITICAL | 9.8 | 1.6% | Mar 16, 2026 | claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2025-14287 | HIGH | 8.8 | 1.5% | Mar 16, 2026 | A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/... |
| CVE-2025-13460 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response disc... |
| CVE-2025-13459 | MEDIUM | 4.9 | 0.4% | Mar 16, 2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc... |
| CVE-2025-13212 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email servi... |
| CVE-2025-12736 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial... |
| CVE-2025-11500 | HIGH | 8.7 | 0.3% | Mar 16, 2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -... |
| CVE-2025-10685 | HIGH | 7.7 | 0.5% | Mar 16, 2026 | Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs... |
| CVE-2025-10461 | MEDIUM | 5.3 | 0.4% | Mar 16, 2026 | Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker ... |
| CVE-2025-8766 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from... |
| CVE-2025-71263 | HIGH | 7.8 | 0.2% | Mar 13, 2026 | In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable h... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now