2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9161 | HIGH | 8.8 | 0.5% | Sep 9, 2025 | A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the ... |
| CVE-2025-9160 | HIGH | 7 | 0.2% | Sep 9, 2025 | A code execution security issue exists in the affected product. An attacker with physical access could abuse the mainten... |
| CVE-2025-9065 | HIGH | 8.8 | 0.4% | Sep 9, 2025 | A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of ... |
| CVE-2025-8008 | MEDIUM | 6.5 | 0.6% | Sep 9, 2025 | A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a For... |
| CVE-2025-8007 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent For... |
| CVE-2025-7970 | HIGH | 7.5 | 0.3% | Sep 9, 2025 | A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within th... |
| CVE-2025-7350 | HIGH | 8.6 | 0.6% | Sep 9, 2025 | A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can ... |
| CVE-2025-8277 | LOW | 3.1 | 0.4% | Sep 9, 2025 | A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess... |
| CVE-2025-48208 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .... |
| CVE-2025-24404 | HIGH | 8.8 | 0.5% | Sep 9, 2025 | XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs t... |
| CVE-2025-10095 | MEDIUM | 5.3 | 0.2% | Sep 9, 2025 | A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically af... |
| CVE-2025-59019 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.... |
| CVE-2025-59018 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,... |
| CVE-2025-59017 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, ... |
| CVE-2025-59016 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0... |
| CVE-2025-59015 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.... |
| CVE-2025-59014 | LOW | 2.7 | 0.3% | Sep 9, 2025 | An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l... |
| CVE-2025-59013 | MEDIUM | 6.1 | 0.2% | Sep 9, 2025 | An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.... |
| CVE-2025-41701 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulat... |
| CVE-2025-40804 | CRITICAL | 9.3 | 0.4% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica... |
| CVE-2025-40803 | LOW | 3.1 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce... |
| CVE-2025-40802 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus... |
| CVE-2025-40798 | HIGH | 8.7 | 0.5% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40797 | HIGH | 8.7 | 0.5% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40796 | HIGH | 8.7 | 0.4% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now