2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61682HIGH8.6Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2025-53837CRITICAL9.9XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-36421MEDIUM5.9IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an...
CVE-2025-36178MEDIUM5.4IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpu...
CVE-2025-36147MEDIUM6.1IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-...
CVE-2025-36076MEDIUM4.3IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source cod...
CVE-2025-36045MEDIUM4.3IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service d...
CVE-2025-33147MEDIUM5.9IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared networ...
CVE-2025-33141MEDIUM6.5IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information fr...
CVE-2025-15399CRITICAL10IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2025-14754HIGH8.8IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on...
CVE-2025-14753HIGH7.5IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send...
CVE-2025-1350MEDIUM5.3IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitiv...
CVE-2025-13882MEDIUM5.3IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM ...
CVE-2025-13533MEDIUM4.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an...
CVE-2025-62167——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33626. Reason: This candidate is a ...
CVE-2025-55787CRITICAL9.8In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
CVE-2025-15697HIGH7.1The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sev...
CVE-2025-59607HIGH7.8Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2025-56566MEDIUM4.6MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile ...
CVE-2025-56565HIGH7.6DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in...
CVE-2025-56563CRITICAL9.8A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts ...
CVE-2025-59953CRITICAL9.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior...
CVE-2025-43936CRITICAL9.1Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthent...
CVE-2025-36591MEDIUM4.4Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now