2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36366 | MEDIUM | 6.5 | 0.4% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by exe... |
| CVE-2025-36353 | MEDIUM | 5.5 | 0.2% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca... |
| CVE-2025-36123 | MEDIUM | 5.5 | 0.1% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca... |
| CVE-2025-36098 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut... |
| CVE-2025-36009 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of... |
| CVE-2025-36001 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut... |
| CVE-2025-2668 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a... |
| CVE-2025-9226 | MEDIUM | 4.6 | 0.4% | Jan 30, 2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s... |
| CVE-2025-6723 | MEDIUM | 5.8 | 0.1% | Jan 30, 2026 | Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con... |
| CVE-2025-12899 | MEDIUM | 6.5 | 0.3% | Jan 30, 2026 | A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re... |
| CVE-2025-15322 | MEDIUM | 4.3 | 0.2% | Jan 30, 2026 | Tanium addressed an improper access controls vulnerability in Tanium Server. |
| CVE-2025-15288 | MEDIUM | 4.3 | 0.2% | Jan 29, 2026 | Tanium addressed an improper access controls vulnerability in Interact. |
| CVE-2025-15550 | MEDIUM | 5.3 | 0.1% | Jan 29, 2026 | birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att... |
| CVE-2025-15549 | MEDIUM | 4.8 | 0.2% | Jan 29, 2026 | FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S... |
| CVE-2025-69749 | MEDIUM | 6.1 | 0.2% | Jan 29, 2026 | Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code. |
| CVE-2025-15548 | MEDIUM | 6.5 | 0.1% | Jan 29, 2026 | Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application... |
| CVE-2025-15543 | MEDIUM | 4.6 | 0.2% | Jan 29, 2026 | Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co... |
| CVE-2025-15542 | MEDIUM | 5.3 | 0.3% | Jan 29, 2026 | Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with... |
| CVE-2025-15541 | MEDIUM | 6.3 | 0.3% | Jan 29, 2026 | Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic... |
| CVE-2025-45160 | MEDIUM | 5.4 | 0.2% | Jan 29, 2026 | A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid f... |
| CVE-2025-15545 | MEDIUM | 6.8 | 0.5% | Jan 29, 2026 | The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such... |
| CVE-2025-71011 | MEDIUM | 6.2 | 0.1% | Jan 29, 2026 | An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of O... |
| CVE-2025-7713 | MEDIUM | 6.1 | 0.2% | Jan 29, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Inte... |
| CVE-2025-71009 | MEDIUM | 6.2 | 0.1% | Jan 29, 2026 | An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to c... |
| CVE-2025-71008 | MEDIUM | 6.2 | 0.1% | Jan 29, 2026 | A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable componen... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now