2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61682 | HIGH | 8.6 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2025-53837 | CRITICAL | 9.9 | 0.6% | Sep 18, 2026 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-36421 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an... |
| CVE-2025-36178 | MEDIUM | 5.4 | — | Sep 18, 2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpu... |
| CVE-2025-36147 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-... |
| CVE-2025-36076 | MEDIUM | 4.3 | — | Sep 18, 2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source cod... |
| CVE-2025-36045 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service d... |
| CVE-2025-33147 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared networ... |
| CVE-2025-33141 | MEDIUM | 6.5 | — | Sep 18, 2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information fr... |
| CVE-2025-15399 | CRITICAL | 10 | 0.3% | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro... |
| CVE-2025-14754 | HIGH | 8.8 | 0.7% | Sep 18, 2026 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on... |
| CVE-2025-14753 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send... |
| CVE-2025-1350 | MEDIUM | 5.3 | 0.4% | Sep 18, 2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitiv... |
| CVE-2025-13882 | MEDIUM | 5.3 | — | Sep 18, 2026 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM ... |
| CVE-2025-13533 | MEDIUM | 4.4 | — | Sep 18, 2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an... |
| CVE-2025-62167 | — | — | — | Sep 17, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33626. Reason: This candidate is a ... |
| CVE-2025-55787 | CRITICAL | 9.8 | 0.3% | Sep 17, 2026 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. |
| CVE-2025-15697 | HIGH | 7.1 | — | Sep 17, 2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sev... |
| CVE-2025-59607 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | Memory Corruption when copying large input data exceeds normal allocation limits. |
| CVE-2025-56566 | MEDIUM | 4.6 | 0.2% | Sep 16, 2026 | MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile ... |
| CVE-2025-56565 | HIGH | 7.6 | 0.2% | Sep 16, 2026 | DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in... |
| CVE-2025-56563 | CRITICAL | 9.8 | 0.4% | Sep 16, 2026 | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts ... |
| CVE-2025-59953 | CRITICAL | 9.8 | 0.8% | Sep 16, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior... |
| CVE-2025-43936 | CRITICAL | 9.1 | 0.5% | Sep 16, 2026 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthent... |
| CVE-2025-36591 | MEDIUM | 4.4 | — | Sep 16, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now