2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10461 | MEDIUM | 5.3 | 0.4% | Mar 16, 2026 | Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker ... |
| CVE-2025-8766 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from... |
| CVE-2025-66249 | MEDIUM | 6.3 | 0.6% | Mar 13, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue... |
| CVE-2025-60012 | MEDIUM | 6.3 | 0.5% | Mar 13, 2026 | Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0... |
| CVE-2025-57849 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being... |
| CVE-2025-15515 | MEDIUM | 5.5 | 0.2% | Mar 13, 2026 | The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific condit... |
| CVE-2025-14811 | MEDIUM | 5.9 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o... |
| CVE-2025-14504 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2025-14483 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2025-13702 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site ... |
| CVE-2025-12454 | MEDIUM | 6.1 | 0.2% | Mar 13, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ... |
| CVE-2025-12453 | MEDIUM | 6.1 | 0.2% | Mar 13, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ... |
| CVE-2025-66955 | MEDIUM | 6.5 | 0.3% | Mar 12, 2026 | Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated ... |
| CVE-2025-61154 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau... |
| CVE-2025-13913 | MEDIUM | 6.8 | 0.3% | Mar 12, 2026 | A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which... |
| CVE-2025-15473 | MEDIUM | 4.3 | 0.2% | Mar 12, 2026 | The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated us... |
| CVE-2025-15038 | MEDIUM | 6.9 | 0.1% | Mar 12, 2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can ... |
| CVE-2025-15037 | MEDIUM | 6.8 | 0.1% | Mar 12, 2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne... |
| CVE-2025-12555 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-13690 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ... |
| CVE-2025-12704 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9... |
| CVE-2025-12697 | MEDIUM | 4.4 | 0.3% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-12576 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18... |
| CVE-2025-12473 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all ... |
| CVE-2025-22850 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now