2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8297HIGH7.2Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated atta...
CVE-2025-8296HIGH7.2SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges...
CVE-2025-5468MEDIUM5.5Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure bef...
CVE-2025-5466MEDIUM4.9XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before ...
CVE-2025-5462HIGH7.5A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, I...
CVE-2025-5456HIGH7.5A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1....
CVE-2025-3831CRITICAL9.8Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
CVE-2025-22834MEDIUM5.3AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Success...
CVE-2025-22830MEDIUM6.7APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful ex...
CVE-2025-43735MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-40770HIGH7A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected applicat...
CVE-2025-40769HIGH7.5A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a...
CVE-2025-40768HIGH7.8A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a...
CVE-2025-40767HIGH7.8A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a...
CVE-2025-40766MEDIUM6.8A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a...
CVE-2025-40764HIGH7.8A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All ver...
CVE-2025-40762HIGH7.8A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All ver...
CVE-2025-40761HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGE...
CVE-2025-40759HIGH8.5A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Upda...
CVE-2025-40753MEDIUM6.8A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWE...
CVE-2025-40752MEDIUM6.8A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWE...
CVE-2025-40751HIGH7.8A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locati...
CVE-2025-40746HIGH7.2A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not pro...
CVE-2025-40743HIGH8.7A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versio...
CVE-2025-40584MEDIUM6.8A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now