2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8875HIGH7.8Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-...
CVE-2025-7972CRITICAL9.1A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘developme...
CVE-2025-7971HIGH7.3A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the speci...
CVE-2025-43983CRITICAL9.1KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/...
CVE-2025-40758HIGH8.7A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendi...
CVE-2025-38745MEDIUM6.5Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log Fi...
CVE-2025-38738HIGH7.8SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment ...
CVE-2025-36613HIGH7.8SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain...
CVE-2025-36612HIGH7.8SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. ...
CVE-2025-27847MEDIUM4.3In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
CVE-2025-27846MEDIUM4.3In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges beca...
CVE-2025-27845CRITICAL9.8In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in e...
CVE-2025-26484MEDIUM4.9Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerabil...
CVE-2025-9036HIGH8.5A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This to...
CVE-2025-7973HIGH8.5A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations...
CVE-2025-7774HIGH8.8A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials c...
CVE-2025-7773HIGH8.8A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number i...
CVE-2025-7353CRITICAL9.3A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Module...
CVE-2025-55675MEDIUM6.5Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization chec...
CVE-2025-55674MEDIUM6.5A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL fun...
CVE-2025-55673MEDIUM4.3When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query f...
CVE-2025-55672MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user...
CVE-2025-43984CRITICAL9.8An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_...
CVE-2025-36581MEDIUM5.5Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of ...
CVE-2025-8963CRITICAL9.8A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now