2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55273MEDIUM4.3HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca...
CVE-2025-55272MEDIUM5.3HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw...
CVE-2025-55271HIGH8.8HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h...
CVE-2025-55270CRITICAL9.8HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ...
CVE-2025-55269CRITICAL9.8HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak...
CVE-2025-55268MEDIUM5.3HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se...
CVE-2025-55267CRITICAL9.8HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio...
CVE-2025-55266MEDIUM6.5HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr...
CVE-2025-55265HIGH7.5HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files...
CVE-2025-41359HIGH7.8Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo...
CVE-2025-41027MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS...
CVE-2025-41026MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS...
CVE-2025-41368HIGH8.1Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us...
CVE-2025-15488MEDIUM6.5The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software al...
CVE-2025-15433MEDIUM6.8The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on ...
CVE-2025-15101HIGH8.8An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen...
CVE-2025-2535——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-36187MEDIUM4.4IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten...
CVE-2025-14684LOW3.3IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat...
CVE-2025-64648MEDIUM5.9IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive informatio...
CVE-2025-64647HIGH7.5IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-64646MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not ...
CVE-2025-36440MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a...
CVE-2025-36438MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 could allow a privileged user to perform unauthorized actions due to improper restrictio...
CVE-2025-36422MEDIUM4.3IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cros...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now