2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11261 | MEDIUM | 6.1 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-61643 | MEDIUM | 6.1 | 0.2% | Feb 3, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchan... |
| CVE-2025-61642 | MEDIUM | 6.1 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-61641 | MEDIUM | 6.1 | 0.3% | Feb 3, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQue... |
| CVE-2025-61640 | MEDIUM | 4.8 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-61639 | MEDIUM | 4.8 | 0.2% | Feb 3, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera... |
| CVE-2025-61638 | MEDIUM | 4.8 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-61637 | MEDIUM | 4.8 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-61636 | MEDIUM | 4.8 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-70960 | MEDIUM | 5.4 | 0.2% | Feb 2, 2026 | A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execu... |
| CVE-2025-70959 | MEDIUM | 5.4 | 0.2% | Feb 2, 2026 | A stored cross-site scripting (XSS) vulnerability in the Jobs module of Tendenci CMS v15.3.7 allows attackers to execute... |
| CVE-2025-70958 | MEDIUM | 6.1 | 0.3% | Feb 2, 2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows at... |
| CVE-2025-6595 | MEDIUM | 4.7 | 0.3% | Feb 2, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-6594 | MEDIUM | 4.7 | 0.3% | Feb 2, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-6590 | MEDIUM | 4.6 | 0.3% | Feb 2, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera... |
| CVE-2025-36436 | MEDIUM | 5.4 | 0.2% | Feb 2, 2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and ... |
| CVE-2025-36238 | MEDIUM | 6 | 0.2% | Feb 2, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could all... |
| CVE-2025-12772 | MEDIUM | 4.9 | 0.3% | Feb 2, 2026 | Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM... |
| CVE-2025-12680 | MEDIUM | 4.9 | 0.2% | Feb 2, 2026 | Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di... |
| CVE-2025-12679 | MEDIUM | 6.5 | 0.1% | Feb 2, 2026 | A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst... |
| CVE-2025-47402 | MEDIUM | 6.5 | 0.1% | Feb 2, 2026 | Transient DOS when processing a received frame with an excessively large authentication information element. |
| CVE-2025-15395 | MEDIUM | 5.4 | 0.2% | Feb 2, 2026 | IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violatio... |
| CVE-2025-7105 | MEDIUM | 5.7 | 0.3% | Feb 2, 2026 | A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork... |
| CVE-2025-6208 | MEDIUM | 5.3 | 0.4% | Feb 2, 2026 | The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption... |
| CVE-2025-71191 | MEDIUM | 5.5 | 0.2% | Jan 31, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now