2025 CVE Vulnerabilities

45,323 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36407MEDIUM5.5IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
CVE-2025-36387MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to c...
CVE-2025-36384HIGH7.8IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to...
CVE-2025-36366MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by exe...
CVE-2025-36365HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific con...
CVE-2025-36353MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca...
CVE-2025-36184HIGH7.2IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu...
CVE-2025-36123MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca...
CVE-2025-36098MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut...
CVE-2025-36070HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to ...
CVE-2025-36009MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of...
CVE-2025-36001MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut...
CVE-2025-2668MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a...
CVE-2025-24293CRITICAL9.2# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote...
CVE-2025-11175HIGH8.8Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v...
CVE-2025-69662HIGH8.6SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po...
CVE-2025-62349HIGH7.5Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au...
CVE-2025-62348HIGH7.8Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by ...
CVE-2025-51958CRITICAL9.8aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com...
CVE-2025-15497LOW3.8Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigge...
CVE-2025-7964CRITICAL9.2After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb...
CVE-2025-4686HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer ...
CVE-2025-9226MEDIUM4.6Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s...
CVE-2025-6723MEDIUM5.8Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con...
CVE-2025-13176HIGH8.4Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now