2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12679 | MEDIUM | 6.5 | 0.1% | Feb 2, 2026 | A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst... |
| CVE-2025-47402 | MEDIUM | 6.5 | 0.1% | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. |
| CVE-2025-15395 | MEDIUM | 5.4 | 0.2% | Feb 2, 2026 | IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio... |
| CVE-2025-7105 | MEDIUM | 5.7 | 0.3% | Feb 2, 2026 | A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork... |
| CVE-2025-6208 | MEDIUM | 5.3 | 0.4% | Feb 2, 2026 | The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption... |
| CVE-2025-71191 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlat... |
| CVE-2025-71190 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe ... |
| CVE-2025-71189 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route al... |
| CVE-2025-71188 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route... |
| CVE-2025-71187 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: fix device leak on probe fa... |
| CVE-2025-71186 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route ... |
| CVE-2025-71185 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am3... |
| CVE-2025-71184 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix NULL dereference on root when tracing in... |
| CVE-2025-71183 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: always detect conflicting inodes when loggin... |
| CVE-2025-71182 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: can: j1939: make j1939_session_activate() fail if d... |
| CVE-2025-71181 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: rust_binder: remove spin_lock() in rust_shrink_free... |
| CVE-2025-71180 | MEDIUM | 5.5 | 0.1% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: counter: interrupt-cnt: Drop IRQF_NO_THREAD flag A... |
| CVE-2025-15525 | MEDIUM | 5.3 | 0.3% | Jan 31, 2026 | The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access o... |
| CVE-2025-15510 | MEDIUM | 5.3 | 0.3% | Jan 31, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2025-36428 | MEDIUM | 5.3 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut... |
| CVE-2025-36427 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to... |
| CVE-2025-36424 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to... |
| CVE-2025-36423 | MEDIUM | 5.5 | 0.2% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a de... |
| CVE-2025-36407 | MEDIUM | 5.5 | 0.3% | Jan 30, 2026 | IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations. |
| CVE-2025-36387 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now