2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64087CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2....
CVE-2025-56353HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), a memory leak occurs due to the broker's failu...
CVE-2025-36419MEDIUM5.3IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks agains...
CVE-2025-36418CRITICAL9.8IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. A...
CVE-2025-36411LOW3.5IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2025-36410MEDIUM4.3IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to s...
CVE-2025-36409MEDIUM5.4IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitra...
CVE-2025-36408MEDIUM6.4IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed ...
CVE-2025-36397MEDIUM5.4IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HT...
CVE-2025-36396MEDIUM5.4IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenti...
CVE-2025-36115MEDIUM6.5IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session...
CVE-2025-36113MEDIUM5.4IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-...
CVE-2025-36066MEDIUM6.1IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-...
CVE-2025-36065MEDIUM6.5IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate ses...
CVE-2025-36063MEDIUM6.5IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate ses...
CVE-2025-36059MEDIUM5.5IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005...
CVE-2025-36058MEDIUM5.5IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005...
CVE-2025-33015HIGH8.8IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploade...
CVE-2025-14883Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-68016. Reason: This candidate is a ...
CVE-2025-58095MEDIUM6.1Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Pre...
CVE-2025-58094MEDIUM6.1Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Pre...
CVE-2025-58093MEDIUM6.1Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Pre...
CVE-2025-58092MEDIUM6.1Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Pre...
CVE-2025-58091MEDIUM6.1Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Pre...
CVE-2025-58090MEDIUM6.1Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Pre...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now