2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41711MEDIUM5.3An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password...
CVE-2025-41710MEDIUM6.5An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi...
CVE-2025-41709CRITICAL9.8An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a...
CVE-2025-40943CRITICAL9.6Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug...
CVE-2025-27769LOW2.6A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC...
CVE-2025-13957HIGH7.5CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code exec...
CVE-2025-13902MEDIUM5.4CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that co...
CVE-2025-13901MEDIUM5.3CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine...
CVE-2025-11739HIGH7.8CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr...
CVE-2025-36173MEDIUM6.1Affected Product(s)Version(s)InfoSphere Data Architect9.2.1
CVE-2025-36105MEDIUM4.4IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s...
CVE-2025-2399MEDIUM5.9Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri...
CVE-2025-11158CRITICAL9.1Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric...
CVE-2025-70973MEDIUM4.8ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated...
CVE-2025-70028HIGH7.5An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov...
CVE-2025-15603——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...
CVE-2025-70031HIGH8.8An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70030HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd...
CVE-2025-68402HIGH8.2FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c...
CVE-2025-62166HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication...
CVE-2025-70032MEDIUM6.1An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70039CRITICAL9.8An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag...
CVE-2025-70038HIGH8.8An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw...
CVE-2025-70034HIGH7.5An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.
CVE-2025-70033MEDIUM5.4An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now