2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59783 | HIGH | 7.2 | 0.9% | Mar 4, 2026 | API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al... |
| CVE-2025-71238 | HIGH | 7.8 | 0.2% | Mar 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ... |
| CVE-2025-70341 | HIGH | 7.8 | 0.2% | Mar 4, 2026 | Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files. |
| CVE-2025-66168 | HIGH | 8.8 | 0.8% | Mar 4, 2026 | WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the follow... |
| CVE-2025-14480 | HIGH | 7.5 | 0.2% | Mar 3, 2026 | IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-13688 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ... |
| CVE-2025-13687 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ... |
| CVE-2025-13686 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ... |
| CVE-2025-36363 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru... |
| CVE-2025-14604 | HIGH | 7.8 | 0.1% | Mar 3, 2026 | IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow... |
| CVE-2025-13616 | HIGH | 7.5 | 0.2% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ... |
| CVE-2025-69765 | HIGH | 7.5 | 0.7% | Mar 3, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus... |
| CVE-2025-67840 | HIGH | 7.2 | 3.7% | Mar 3, 2026 | Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil... |
| CVE-2025-63912 | HIGH | 7.5 | 0.1% | Mar 3, 2026 | Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da... |
| CVE-2025-63911 | HIGH | 7.2 | 2.3% | Mar 3, 2026 | Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti... |
| CVE-2025-63910 | HIGH | 7.2 | 0.4% | Mar 3, 2026 | An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al... |
| CVE-2025-63909 | HIGH | 7.8 | 0.3% | Mar 3, 2026 | Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.... |
| CVE-2025-62817 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ... |
| CVE-2025-66680 | HIGH | 7.1 | 0.2% | Mar 3, 2026 | An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele... |
| CVE-2025-66363 | HIGH | 7.5 | 0.5% | Mar 3, 2026 | An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit... |
| CVE-2025-62814 | HIGH | 7.5 | 0.5% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ... |
| CVE-2025-64736 | HIGH | 7.1 | 0.2% | Mar 3, 2026 | An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma... |
| CVE-2025-52365 | HIGH | 7.8 | 0.5% | Mar 3, 2026 | A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ... |
| CVE-2025-15595 | HIGH | 7.8 | 0.1% | Mar 3, 2026 | Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions. |
| CVE-2025-12345 | HIGH | 8.8 | 0.7% | Mar 3, 2026 | A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the functio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now