2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14504 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2025-14483 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2025-13779 | HIGH | 8.3 | 0.3% | Mar 13, 2026 | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW... |
| CVE-2025-13778 | HIGH | 7.1 | 0.3% | Mar 13, 2026 | Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW... |
| CVE-2025-13777 | HIGH | 8.3 | 0.2% | Mar 13, 2026 | Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW... |
| CVE-2025-13726 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke... |
| CVE-2025-13723 | HIGH | 7.5 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o... |
| CVE-2025-13718 | HIGH | 7.5 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke... |
| CVE-2025-13702 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site ... |
| CVE-2025-13337 | — | — | — | Mar 13, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12455 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability co... |
| CVE-2025-12454 | MEDIUM | 6.1 | 0.2% | Mar 13, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ... |
| CVE-2025-12453 | MEDIUM | 6.1 | 0.2% | Mar 13, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ... |
| CVE-2025-70873 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier al... |
| CVE-2025-70245 | CRITICAL | 9.8 | 0.6% | Mar 12, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode. |
| CVE-2025-66955 | MEDIUM | 6.5 | 0.3% | Mar 12, 2026 | Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated ... |
| CVE-2025-61154 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau... |
| CVE-2025-13913 | MEDIUM | 6.8 | 0.3% | Mar 12, 2026 | A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which... |
| CVE-2025-13462 | LOW | 3.3 | 0.2% | Mar 12, 2026 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi... |
| CVE-2025-15473 | MEDIUM | 4.3 | 0.2% | Mar 12, 2026 | The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated us... |
| CVE-2025-15038 | MEDIUM | 6.9 | 0.1% | Mar 12, 2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can ... |
| CVE-2025-15037 | MEDIUM | 6.8 | 0.1% | Mar 12, 2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne... |
| CVE-2025-59388 | CRITICAL | 9.8 | 0.5% | Mar 12, 2026 | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can th... |
| CVE-2025-62328 | LOW | 3.7 | 0.2% | Mar 11, 2026 | HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by defa... |
| CVE-2025-70041 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now