2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55266 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr... |
| CVE-2025-55265 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files... |
| CVE-2025-41359 | HIGH | 7.8 | 0.2% | Mar 26, 2026 | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo... |
| CVE-2025-41027 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS... |
| CVE-2025-41026 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS... |
| CVE-2025-41368 | HIGH | 8.1 | 0.6% | Mar 26, 2026 | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us... |
| CVE-2025-15488 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software al... |
| CVE-2025-15433 | MEDIUM | 6.8 | 0.4% | Mar 26, 2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on ... |
| CVE-2025-15101 | HIGH | 8.8 | 0.9% | Mar 26, 2026 | An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen... |
| CVE-2025-2535 | — | — | — | Mar 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-36187 | MEDIUM | 4.4 | 0.2% | Mar 25, 2026 | IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten... |
| CVE-2025-14684 | LOW | 3.3 | 0.1% | Mar 25, 2026 | IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat... |
| CVE-2025-64648 | MEDIUM | 5.9 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive informatio... |
| CVE-2025-64647 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-64646 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not ... |
| CVE-2025-36440 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a... |
| CVE-2025-36438 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio... |
| CVE-2025-36422 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cros... |
| CVE-2025-36258 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive informat... |
| CVE-2025-14974 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR)... |
| CVE-2025-14917 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov... |
| CVE-2025-14915 | HIGH | 7.2 | 0.5% | Mar 25, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affecte... |
| CVE-2025-14912 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This ma... |
| CVE-2025-14810 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been mod... |
| CVE-2025-14808 | LOW | 3.1 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now