2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71355HIGH7.6Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat...
CVE-2025-71352HIGH8.1picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce...
CVE-2025-71350HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met...
CVE-2025-71349HIGH8.1picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att...
CVE-2025-36359MEDIUM6.5IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow...
CVE-2025-36336MEDIUM5.9IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob...
CVE-2025-36333MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio...
CVE-2025-36328MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information w...
CVE-2025-36327MEDIUM6.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls a...
CVE-2025-36324MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may al...
CVE-2025-36323MEDIUM5.4IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2025-36321MEDIUM5.7IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject...
CVE-2025-36320MEDIUM6.4IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerabilit...
CVE-2025-36319MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial u...
CVE-2025-12530MEDIUM5.9IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow a...
CVE-2025-36372MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-53648MEDIUM5.4SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate fi...
CVE-2025-7406HIGH7.8Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administr...
CVE-2025-24816MEDIUM6.5Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. ...
CVE-2025-24815HIGH7.8Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ...
CVE-2025-7386MEDIUM6.8Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51...
CVE-2025-2902HIGH8.3Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hit...
CVE-2025-0824LOW3.7Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue...
CVE-2025-59868MEDIUM5.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an...
CVE-2025-32423MEDIUM5.3AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now