2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36136 | MEDIUM | 5.5 | 0.1% | Nov 7, 2025 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could... |
| CVE-2025-36135 | MEDIUM | 5.4 | 0.1% | Nov 7, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gatewa... |
| CVE-2025-36131 | MEDIUM | 4.6 | 0.2% | Nov 7, 2025 | IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ... |
| CVE-2025-36008 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-36006 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI... |
| CVE-2025-33012 | HIGH | 8.8 | 0.1% | Nov 7, 2025 | IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux coul... |
| CVE-2025-2534 | HIGH | 7.5 | 0.2% | Nov 7, 2025 | IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ... |
| CVE-2025-12890 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the ... |
| CVE-2025-9458 | HIGH | 7.8 | 0.2% | Nov 7, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili... |
| CVE-2025-64430 | HIGH | 7.5 | 0.6% | Nov 7, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.... |
| CVE-2025-64347 | HIGH | 7.5 | 0.3% | Nov 7, 2025 | Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. ... |
| CVE-2025-63718 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient... |
| CVE-2025-63716 | MEDIUM | 6.5 | 0.1% | Nov 7, 2025 | The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho... |
| CVE-2025-63714 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute... |
| CVE-2025-63713 | MEDIUM | 6.1 | 0.3% | Nov 7, 2025 | Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary... |
| CVE-2025-57697 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image... |
| CVE-2025-12873 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a... |
| CVE-2025-12858 | — | — | — | Nov 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-12829 | MEDIUM | 6.9 | 0.1% | Nov 7, 2025 | An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an... |
| CVE-2025-7719 | MEDIUM | 5.3 | 0.3% | Nov 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on... |
| CVE-2025-63785 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2... |
| CVE-2025-63784 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback... |
| CVE-2025-57698 | HIGH | 7.5 | 0.7% | Nov 7, 2025 | AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the ... |
| CVE-2025-3222 | CRITICAL | 9.3 | 0.5% | Nov 7, 2025 | Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue ... |
| CVE-2025-12862 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now