2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36173 | MEDIUM | 6.1 | 0.1% | Mar 10, 2026 | Affected Product(s)Version(s)InfoSphere Data Architect9.2.1 |
| CVE-2025-36105 | MEDIUM | 4.4 | 0.1% | Mar 10, 2026 | IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s... |
| CVE-2025-2399 | MEDIUM | 5.9 | 0.6% | Mar 10, 2026 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri... |
| CVE-2025-70973 | MEDIUM | 4.8 | 0.2% | Mar 9, 2026 | ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated... |
| CVE-2025-70032 | MEDIUM | 6.1 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. |
| CVE-2025-70033 | MEDIUM | 5.4 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed ... |
| CVE-2025-70037 | MEDIUM | 6.1 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This a... |
| CVE-2025-70060 | MEDIUM | 5.4 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v... |
| CVE-2025-70050 | MEDIUM | 6.5 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh... |
| CVE-2025-70040 | MEDIUM | 5.3 | 0.2% | Mar 9, 2026 | An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-... |
| CVE-2025-69648 | MEDIUM | 6.2 | 0.2% | Mar 9, 2026 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor... |
| CVE-2025-69647 | MEDIUM | 6.2 | 0.2% | Mar 9, 2026 | GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor... |
| CVE-2025-40638 | MEDIUM | 6.1 | 0.2% | Mar 9, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker... |
| CVE-2025-41763 | MEDIUM | 6.5 | 0.2% | Mar 9, 2026 | A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl... |
| CVE-2025-41762 | MEDIUM | 6.2 | 0.1% | Mar 9, 2026 | An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauth... |
| CVE-2025-41760 | MEDIUM | 4.9 | 0.3% | Mar 9, 2026 | An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an ... |
| CVE-2025-41759 | MEDIUM | 4.9 | 0.3% | Mar 9, 2026 | An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these... |
| CVE-2025-41755 | MEDIUM | 6.5 | 0.5% | Mar 9, 2026 | A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system.... |
| CVE-2025-41754 | MEDIUM | 6.5 | 0.3% | Mar 9, 2026 | A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo... |
| CVE-2025-69653 | MEDIUM | 6.5 | 0.2% | Mar 6, 2026 | A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb... |
| CVE-2025-69652 | MEDIUM | 6.2 | 0.2% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b... |
| CVE-2025-69651 | MEDIUM | 5.5 | 0.2% | Mar 6, 2026 | GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ... |
| CVE-2025-69646 | MEDIUM | 5.5 | 0.2% | Mar 6, 2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_... |
| CVE-2025-69645 | MEDIUM | 5.5 | 0.2% | Mar 6, 2026 | Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug ... |
| CVE-2025-69644 | MEDIUM | 5 | 0.1% | Mar 6, 2026 | An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now