2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36253 | HIGH | 7.5 | 0.2% | Feb 2, 2026 | IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-36238 | MEDIUM | 6 | 0.2% | Feb 2, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could all... |
| CVE-2025-36194 | LOW | 3.3 | 0.1% | Feb 2, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expos... |
| CVE-2025-13096 | HIGH | 7.1 | 0.5% | Feb 2, 2026 | IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF... |
| CVE-2025-12772 | MEDIUM | 4.9 | 0.3% | Feb 2, 2026 | Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM... |
| CVE-2025-12680 | MEDIUM | 4.9 | 0.2% | Feb 2, 2026 | Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di... |
| CVE-2025-12679 | MEDIUM | 6.5 | 0.1% | Feb 2, 2026 | A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst... |
| CVE-2025-47402 | MEDIUM | 6.5 | 0.1% | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. |
| CVE-2025-47399 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters. |
| CVE-2025-47398 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers... |
| CVE-2025-47397 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. |
| CVE-2025-47366 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. |
| CVE-2025-47364 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory corruption while calculating offset from partition start point. |
| CVE-2025-47363 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory corruption when calculating oversized partition sizes without proper checks. |
| CVE-2025-47359 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption when multiple threads simultaneously access a memory free API. |
| CVE-2025-47358 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad... |
| CVE-2025-15395 | MEDIUM | 5.4 | 0.2% | Feb 2, 2026 | IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio... |
| CVE-2025-14914 | HIGH | 7.6 | 0.4% | Feb 2, 2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive... |
| CVE-2025-8587 | CRITICAL | 9.8 | 0.3% | Feb 2, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech... |
| CVE-2025-7105 | MEDIUM | 5.7 | 0.3% | Feb 2, 2026 | A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork... |
| CVE-2025-6208 | MEDIUM | 5.3 | 0.4% | Feb 2, 2026 | The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption... |
| CVE-2025-10279 | HIGH | 7 | 0.2% | Feb 2, 2026 | In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure wor... |
| CVE-2025-9974 | HIGH | 8 | 0.4% | Feb 2, 2026 | The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users t... |
| CVE-2025-15396 | HIGH | 7.1 | 0.2% | Feb 2, 2026 | The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them bac... |
| CVE-2025-15030 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now