2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55266MEDIUM6.5HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr...
CVE-2025-55265HIGH7.5HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files...
CVE-2025-41359HIGH7.8Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo...
CVE-2025-41027MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS...
CVE-2025-41026MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS...
CVE-2025-41368HIGH8.1Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us...
CVE-2025-15488MEDIUM6.5The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software al...
CVE-2025-15433MEDIUM6.8The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on ...
CVE-2025-15101HIGH8.8An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen...
CVE-2025-2535Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-36187MEDIUM4.4IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten...
CVE-2025-14684LOW3.3IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat...
CVE-2025-64648MEDIUM5.9IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive informatio...
CVE-2025-64647HIGH7.5IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-64646MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not ...
CVE-2025-36440MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a...
CVE-2025-36438MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio...
CVE-2025-36422MEDIUM4.3IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cros...
CVE-2025-36258MEDIUM5.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive informat...
CVE-2025-14974HIGH7.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR)...
CVE-2025-14917CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov...
CVE-2025-14915HIGH7.2IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affecte...
CVE-2025-14912MEDIUM5.4IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This ma...
CVE-2025-14810MEDIUM6.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been mod...
CVE-2025-14808LOW3.1IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now