2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36366MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by exe...
CVE-2025-36365HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific con...
CVE-2025-36353MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca...
CVE-2025-36184HIGH7.2IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu...
CVE-2025-36123MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca...
CVE-2025-36098MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut...
CVE-2025-36070HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to ...
CVE-2025-36009MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of...
CVE-2025-36001MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut...
CVE-2025-2668MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a...
CVE-2025-24293CRITICAL9.2# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote...
CVE-2025-11175HIGH8.8Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v...
CVE-2025-69662HIGH8.6SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po...
CVE-2025-62349HIGH7.5Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au...
CVE-2025-62348HIGH7.8Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by ...
CVE-2025-51958CRITICAL9.8aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com...
CVE-2025-15497LOW3.8Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigge...
CVE-2025-7964CRITICAL9.2After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb...
CVE-2025-4686HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer ...
CVE-2025-9226MEDIUM4.6Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s...
CVE-2025-6723MEDIUM5.8Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con...
CVE-2025-13176HIGH8.4Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.
CVE-2025-26385CRITICAL9.5Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com...
CVE-2025-1395HIGH8.2Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog...
CVE-2025-12899MEDIUM6.5A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now