2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-36184HIGH7.2IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu...
CVE-2025-36070HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to ...
CVE-2025-11175HIGH8.8Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v...
CVE-2025-69662HIGH8.6SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po...
CVE-2025-62349HIGH7.5Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au...
CVE-2025-62348HIGH7.8Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by ...
CVE-2025-4686HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer ...
CVE-2025-13176HIGH8.4Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.
CVE-2025-1395HIGH8.2Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog...
CVE-2025-69604HIGH7.8An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in...
CVE-2025-69516HIGH8.8A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica...
CVE-2025-63658HIGH7.5A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to...
CVE-2025-63657HIGH7.5An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke...
CVE-2025-63656HIGH7.5An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers ...
CVE-2025-63655HIGH7.5A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att...
CVE-2025-63653HIGH7.5An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker...
CVE-2025-63652HIGH7.5A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to ...
CVE-2025-63651HIGH7.5A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t...
CVE-2025-63650HIGH7.5An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t...
CVE-2025-63649HIGH7.5An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi...
CVE-2025-13399HIGH8.8A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force...
CVE-2025-62514HIGH7.1Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3....
CVE-2025-13905HIGH7CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse s...
CVE-2025-7014HIGH8.8Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect...
CVE-2025-14975HIGH8.1The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now