2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33130 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras... |
| CVE-2025-33124 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras... |
| CVE-2025-33101 | MEDIUM | 5.9 | 0.2% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniqu... |
| CVE-2025-27904 | MEDIUM | 6.5 | 0.1% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to... |
| CVE-2025-27903 | MEDIUM | 5.9 | 0.1% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data i... |
| CVE-2025-27901 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to... |
| CVE-2025-27900 | MEDIUM | 6.1 | 0.1% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an ... |
| CVE-2025-27899 | MEDIUM | 5.3 | 0.2% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that coul... |
| CVE-2025-27898 | MEDIUM | 6.3 | 0.2% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an aut... |
| CVE-2025-36019 | MEDIUM | 6.1 | 0.2% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an ... |
| CVE-2025-36018 | MEDIUM | 6.5 | 0.1% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an att... |
| CVE-2025-12755 | MEDIUM | 4 | 0.1% | Feb 17, 2026 | IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2... |
| CVE-2025-36425 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could ... |
| CVE-2025-14689 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated use... |
| CVE-2025-13867 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could ... |
| CVE-2025-70829 | MEDIUM | 5.7 | 0.4% | Feb 17, 2026 | An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via ... |
| CVE-2025-7706 | MEDIUM | 6.1 | 0.2% | Feb 17, 2026 | Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li... |
| CVE-2025-8303 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Softwar... |
| CVE-2025-65717 | MEDIUM | 4.3 | 0.5% | Feb 16, 2026 | An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction w... |
| CVE-2025-14350 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership whe... |
| CVE-2025-2418 | MEDIUM | 4.3 | 0.2% | Feb 16, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber Defense Inc. Web Application Firewall a... |
| CVE-2025-13821 | MEDIUM | 5.7 | 0.2% | Feb 16, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket ... |
| CVE-2025-59905 | MEDIUM | 6.1 | 0.1% | Feb 16, 2026 | Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endp... |
| CVE-2025-59904 | MEDIUM | 5.4 | 0.1% | Feb 16, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kFo... |
| CVE-2025-59903 | MEDIUM | 5.4 | 0.1% | Feb 16, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now