2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55273 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca... |
| CVE-2025-55272 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw... |
| CVE-2025-55271 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h... |
| CVE-2025-55270 | CRITICAL | 9.8 | 1.0% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ... |
| CVE-2025-55269 | CRITICAL | 9.8 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak... |
| CVE-2025-55268 | MEDIUM | 5.3 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se... |
| CVE-2025-55267 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio... |
| CVE-2025-55266 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr... |
| CVE-2025-55265 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files... |
| CVE-2025-41359 | HIGH | 7.8 | 0.2% | Mar 26, 2026 | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo... |
| CVE-2025-41027 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS... |
| CVE-2025-41026 | MEDIUM | 6.1 | 0.2% | Mar 26, 2026 | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS... |
| CVE-2025-41368 | HIGH | 8.1 | 0.6% | Mar 26, 2026 | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us... |
| CVE-2025-15488 | MEDIUM | 6.5 | 0.3% | Mar 26, 2026 | The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software al... |
| CVE-2025-15433 | MEDIUM | 6.8 | 0.4% | Mar 26, 2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on ... |
| CVE-2025-15101 | HIGH | 8.8 | 0.9% | Mar 26, 2026 | An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen... |
| CVE-2025-2535 | — | — | — | Mar 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-36187 | MEDIUM | 4.4 | 0.2% | Mar 25, 2026 | IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten... |
| CVE-2025-14684 | LOW | 3.3 | 0.1% | Mar 25, 2026 | IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat... |
| CVE-2025-64648 | MEDIUM | 5.9 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive informatio... |
| CVE-2025-64647 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-64646 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not ... |
| CVE-2025-36440 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a... |
| CVE-2025-36438 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio... |
| CVE-2025-36422 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cros... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now