2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36366MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by exe...
CVE-2025-36353MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca...
CVE-2025-36123MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a loca...
CVE-2025-36098MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut...
CVE-2025-36009MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of...
CVE-2025-36001MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut...
CVE-2025-2668MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service a...
CVE-2025-9226MEDIUM4.6Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s...
CVE-2025-6723MEDIUM5.8Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access con...
CVE-2025-12899MEDIUM6.5A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re...
CVE-2025-15322MEDIUM4.3Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2025-15288MEDIUM4.3Tanium addressed an improper access controls vulnerability in Interact.
CVE-2025-15550MEDIUM5.3birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att...
CVE-2025-15549MEDIUM4.8FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S...
CVE-2025-69749MEDIUM6.1Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.
CVE-2025-15548MEDIUM6.5Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application...
CVE-2025-15543MEDIUM4.6Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co...
CVE-2025-15542MEDIUM5.3Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with...
CVE-2025-15541MEDIUM6.3Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic...
CVE-2025-45160MEDIUM5.4A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid f...
CVE-2025-15545MEDIUM6.8The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such...
CVE-2025-71011MEDIUM6.2An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of O...
CVE-2025-7713MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Inte...
CVE-2025-71009MEDIUM6.2An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to c...
CVE-2025-71008MEDIUM6.2A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable componen...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now