2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36187 | MEDIUM | 4.4 | 0.2% | Mar 25, 2026 | IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten... |
| CVE-2025-64648 | MEDIUM | 5.9 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive informatio... |
| CVE-2025-64646 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not ... |
| CVE-2025-36440 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a... |
| CVE-2025-36438 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio... |
| CVE-2025-36422 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cros... |
| CVE-2025-36258 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive informat... |
| CVE-2025-14912 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This ma... |
| CVE-2025-14810 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been mod... |
| CVE-2025-14807 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper v... |
| CVE-2025-14790 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due ... |
| CVE-2025-12708 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user. |
| CVE-2025-14595 | MEDIUM | 4.3 | 0.3% | Mar 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.1... |
| CVE-2025-13436 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2025-13078 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and ... |
| CVE-2025-40842 | MEDIUM | 6.1 | 0.1% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exp... |
| CVE-2025-40841 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which,... |
| CVE-2025-43534 | MEDIUM | 6.8 | 0.2% | Mar 25, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 2... |
| CVE-2025-33242 | MEDIUM | 5.9 | 0.3% | Mar 24, 2026 | NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr... |
| CVE-2025-33216 | MEDIUM | 6.8 | 0.3% | Mar 24, 2026 | NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an i... |
| CVE-2025-33215 | MEDIUM | 6.8 | 0.3% | Mar 24, 2026 | NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of... |
| CVE-2025-60948 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st... |
| CVE-2025-52204 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerI... |
| CVE-2025-6229 | MEDIUM | 6.4 | 0.2% | Mar 23, 2026 | The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl... |
| CVE-2025-13997 | MEDIUM | 5.3 | 0.2% | Mar 23, 2026 | The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now