2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9161HIGH8.8A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the ...
CVE-2025-9160HIGH7A code execution security issue exists in the affected product. An attacker with physical access could abuse the mainten...
CVE-2025-9065HIGH8.8A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of ...
CVE-2025-8008MEDIUM6.5A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a For...
CVE-2025-8007MEDIUM6.5A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent For...
CVE-2025-7970HIGH7.5A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within th...
CVE-2025-7350HIGH8.6A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can ...
CVE-2025-8277LOW3.1A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess...
CVE-2025-48208HIGH8.8Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat ....
CVE-2025-24404HIGH8.8XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs t...
CVE-2025-10095MEDIUM5.3A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically af...
CVE-2025-59019MEDIUM4.3Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0....
CVE-2025-59018MEDIUM6.5Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,...
CVE-2025-59017HIGH8.8Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, ...
CVE-2025-59016MEDIUM4.3Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0...
CVE-2025-59015MEDIUM6.5A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13....
CVE-2025-59014LOW2.7An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l...
CVE-2025-59013MEDIUM6.1An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11....
CVE-2025-41701HIGH7.8An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulat...
CVE-2025-40804CRITICAL9.3A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica...
CVE-2025-40803LOW3.1A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce...
CVE-2025-40802MEDIUM4.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be sus...
CVE-2025-40798HIGH8.7A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2025-40797HIGH8.7A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2025-40796HIGH8.7A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now