2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27900MEDIUM6.1IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an ...
CVE-2025-27899MEDIUM5.3IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that coul...
CVE-2025-27898MEDIUM6.3IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an aut...
CVE-2025-36019MEDIUM6.1IBM Concert 1.0.0 through 2.1.0 for Z hub framework is vulnerable to cross-site scripting. This vulnerability allows an ...
CVE-2025-36018MEDIUM6.5IBM Concert 1.0.0 through 2.1.0 for Z hub component is vulnerable to cross-site request forgery which could allow an att...
CVE-2025-12755MEDIUM4IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2...
CVE-2025-36425MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could ...
CVE-2025-14689MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated use...
CVE-2025-13867MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could ...
CVE-2025-70829MEDIUM5.7An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via ...
CVE-2025-7706MEDIUM6.1Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li...
CVE-2025-8303MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Softwar...
CVE-2025-65717MEDIUM4.3An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction w...
CVE-2025-14350MEDIUM4.3Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership whe...
CVE-2025-2418MEDIUM4.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall a...
CVE-2025-13821MEDIUM5.7Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket ...
CVE-2025-59905MEDIUM6.1Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endp...
CVE-2025-59904MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kFo...
CVE-2025-59903MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This ...
CVE-2025-32063MEDIUM6.8There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens d...
CVE-2025-32060MEDIUM6.7The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on be...
CVE-2025-71223MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ...
CVE-2025-71222MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push ...
CVE-2025-71204MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in parse_durable_hand...
CVE-2025-71202MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kerne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now