2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36366 | MEDIUM | 6.5 | 0.4% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by exe... |
| CVE-2025-36365 | HIGH | 7.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific con... |
| CVE-2025-36353 | MEDIUM | 5.5 | 0.2% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca... |
| CVE-2025-36184 | HIGH | 7.2 | 0.5% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu... |
| CVE-2025-36123 | MEDIUM | 5.5 | 0.1% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca... |
| CVE-2025-36098 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut... |
| CVE-2025-36070 | HIGH | 7.5 | 0.4% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to ... |
| CVE-2025-36009 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of... |
| CVE-2025-36001 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut... |
| CVE-2025-2668 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a... |
| CVE-2025-24293 | CRITICAL | 9.2 | 2.4% | Jan 30, 2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote... |
| CVE-2025-11175 | HIGH | 8.8 | 0.4% | Jan 30, 2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v... |
| CVE-2025-69662 | HIGH | 8.6 | 0.4% | Jan 30, 2026 | SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po... |
| CVE-2025-62349 | HIGH | 7.5 | 0.4% | Jan 30, 2026 | Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au... |
| CVE-2025-62348 | HIGH | 7.8 | 0.2% | Jan 30, 2026 | Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by ... |
| CVE-2025-51958 | CRITICAL | 9.8 | 0.6% | Jan 30, 2026 | aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com... |
| CVE-2025-15497 | LOW | 3.8 | 0.3% | Jan 30, 2026 | Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigge... |
| CVE-2025-7964 | CRITICAL | 9.2 | 0.3% | Jan 30, 2026 | After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb... |
| CVE-2025-4686 | HIGH | 8.6 | 0.3% | Jan 30, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer ... |
| CVE-2025-9226 | MEDIUM | 4.6 | 0.4% | Jan 30, 2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s... |
| CVE-2025-6723 | MEDIUM | 5.8 | 0.1% | Jan 30, 2026 | Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con... |
| CVE-2025-13176 | HIGH | 8.4 | 0.2% | Jan 30, 2026 | Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL. |
| CVE-2025-26385 | CRITICAL | 9.5 | 1.4% | Jan 30, 2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com... |
| CVE-2025-1395 | HIGH | 8.2 | 0.3% | Jan 30, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog... |
| CVE-2025-12899 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now