2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36336 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob... |
| CVE-2025-36333 | MEDIUM | 4.3 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio... |
| CVE-2025-36328 | MEDIUM | 4.3 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information w... |
| CVE-2025-36327 | MEDIUM | 6.5 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls a... |
| CVE-2025-36324 | MEDIUM | 4.3 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may al... |
| CVE-2025-36323 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2025-36321 | MEDIUM | 5.7 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject... |
| CVE-2025-36320 | MEDIUM | 6.4 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerabilit... |
| CVE-2025-36319 | MEDIUM | 4.3 | 0.4% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to cause a temporary denial u... |
| CVE-2025-12530 | MEDIUM | 5.9 | 0.1% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow a... |
| CVE-2025-36372 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-53648 | MEDIUM | 5.4 | — | Jun 30, 2026 | SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate fi... |
| CVE-2025-24816 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. ... |
| CVE-2025-7386 | MEDIUM | 6.8 | 0.2% | Jun 29, 2026 | Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51... |
| CVE-2025-59868 | MEDIUM | 5.5 | 0.1% | Jun 27, 2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an... |
| CVE-2025-32423 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-32394 | MEDIUM | 5.3 | — | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-68075 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions. |
| CVE-2025-68074 | MEDIUM | 6.5 | — | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions. |
| CVE-2025-66123 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions. |
| CVE-2025-64637 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | Unauthenticated Content Injection in Auros Core <= 5.3.1 versions. |
| CVE-2025-64636 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions. |
| CVE-2025-63079 | MEDIUM | 4.3 | — | Jun 26, 2026 | Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions. |
| CVE-2025-63078 | MEDIUM | 4.3 | — | Jun 26, 2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. |
| CVE-2025-63041 | MEDIUM | 5.4 | — | Jun 26, 2026 | Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now