2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36253HIGH7.5IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-36238MEDIUM6IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could all...
CVE-2025-36194LOW3.3IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expos...
CVE-2025-13096HIGH7.1IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF...
CVE-2025-12772MEDIUM4.9Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM...
CVE-2025-12680MEDIUM4.9Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di...
CVE-2025-12679MEDIUM6.5A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst...
CVE-2025-47402MEDIUM6.5Transient DOS when processing a received frame with an excessively large authentication information element.
CVE-2025-47399HIGH7.8Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.
CVE-2025-47398HIGH7.8Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers...
CVE-2025-47397HIGH7.8Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
CVE-2025-47366HIGH7.8Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-47364HIGH7.8Memory corruption while calculating offset from partition start point.
CVE-2025-47363HIGH7.8Memory corruption when calculating oversized partition sizes without proper checks.
CVE-2025-47359HIGH7.8Memory Corruption when multiple threads simultaneously access a memory free API.
CVE-2025-47358HIGH7.8Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad...
CVE-2025-15395MEDIUM5.4IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio...
CVE-2025-14914HIGH7.6IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive...
CVE-2025-8587CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech...
CVE-2025-7105MEDIUM5.7A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork...
CVE-2025-6208MEDIUM5.3The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption...
CVE-2025-10279HIGH7In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure wor...
CVE-2025-9974HIGH8The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users t...
CVE-2025-15396HIGH7.1The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them bac...
CVE-2025-15030CRITICAL9.8The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now