2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-36136MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2025-36135MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gatewa...
CVE-2025-36131MEDIUM4.6IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ...
CVE-2025-36008MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-36006MEDIUM6.5IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI...
CVE-2025-33012HIGH8.8IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux coul...
CVE-2025-2534HIGH7.5IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ...
CVE-2025-12890MEDIUM6.5Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the ...
CVE-2025-9458HIGH7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili...
CVE-2025-64430HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2....
CVE-2025-64347HIGH7.5Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. ...
CVE-2025-63718MEDIUM6.5A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient...
CVE-2025-63716MEDIUM6.5The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho...
CVE-2025-63714MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute...
CVE-2025-63713MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary...
CVE-2025-57697MEDIUM6.5AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image...
CVE-2025-12873CRITICAL9.8A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a...
CVE-2025-12858Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-12829MEDIUM6.9An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an...
CVE-2025-7719MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on...
CVE-2025-63785MEDIUM6.1A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2...
CVE-2025-63784MEDIUM6.5An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback...
CVE-2025-57698HIGH7.5AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the ...
CVE-2025-3222CRITICAL9.3Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue ...
CVE-2025-12862CRITICAL9.8A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now