2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67478 | HIGH | 8.8 | 0.3% | Feb 3, 2026 | Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserM... |
| CVE-2025-58383 | HIGH | 7.2 | 0.5% | Feb 3, 2026 | A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind... |
| CVE-2025-58382 | HIGH | 7.2 | 0.6% | Feb 3, 2026 | A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabri... |
| CVE-2025-12774 | HIGH | 7.5 | 0.2% | Feb 3, 2026 | A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries... |
| CVE-2025-15556 | HIGH | 7.5 | 1.3% | Feb 3, 2026 | Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability... |
| CVE-2025-69207 | HIGH | 7.1 | 0.4% | Feb 2, 2026 | Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows... |
| CVE-2025-36253 | HIGH | 7.5 | 0.2% | Feb 2, 2026 | IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-13096 | HIGH | 7.1 | 0.5% | Feb 2, 2026 | IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF... |
| CVE-2025-47399 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters. |
| CVE-2025-47398 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers... |
| CVE-2025-47397 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. |
| CVE-2025-47366 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. |
| CVE-2025-47364 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory corruption while calculating offset from partition start point. |
| CVE-2025-47363 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory corruption when calculating oversized partition sizes without proper checks. |
| CVE-2025-47359 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption when multiple threads simultaneously access a memory free API. |
| CVE-2025-47358 | HIGH | 7.8 | 0.1% | Feb 2, 2026 | Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad... |
| CVE-2025-14914 | HIGH | 7.6 | 0.4% | Feb 2, 2026 | IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive... |
| CVE-2025-10279 | HIGH | 7 | 0.2% | Feb 2, 2026 | In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure wor... |
| CVE-2025-9974 | HIGH | 8 | 0.4% | Feb 2, 2026 | The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users t... |
| CVE-2025-15396 | HIGH | 7.1 | 0.2% | Feb 2, 2026 | The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them bac... |
| CVE-2025-13348 | HIGH | 8.5 | 0.1% | Feb 2, 2026 | An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerabilit... |
| CVE-2025-14554 | HIGH | 7.2 | 0.3% | Jan 31, 2026 | The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-36442 | HIGH | 7.5 | 0.4% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a... |
| CVE-2025-36384 | HIGH | 7.8 | 0.2% | Jan 30, 2026 | IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to... |
| CVE-2025-36365 | HIGH | 7.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now