2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52182 | HIGH | 7.5 | — | Aug 20, 2026 | The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability. |
| CVE-2025-62306 | MEDIUM | 5 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a... |
| CVE-2025-62300 | MEDIUM | 5.9 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can... |
| CVE-2025-62299 | MEDIUM | 6.6 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces... |
| CVE-2025-62307 | MEDIUM | 5.4 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, ... |
| CVE-2025-53999 | MEDIUM | 6.5 | — | Aug 20, 2026 | Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. |
| CVE-2025-15689 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. |
| CVE-2025-15688 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. |
| CVE-2025-15637 | HIGH | 8.1 | — | Aug 20, 2026 | Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
| CVE-2025-14601 | HIGH | 8.6 | — | Aug 20, 2026 | An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execu... |
| CVE-2025-14602 | MEDIUM | 5.3 | — | Aug 20, 2026 | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a... |
| CVE-2025-36398 | MEDIUM | 5.4 | — | Aug 19, 2026 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe... |
| CVE-2025-36255 | HIGH | 8.8 | — | Aug 19, 2026 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe... |
| CVE-2025-36254 | HIGH | 7.4 | — | Aug 19, 2026 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attac... |
| CVE-2025-14603 | HIGH | 8.8 | — | Aug 19, 2026 | The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable ... |
| CVE-2025-14600 | CRITICAL | 9.3 | — | Aug 19, 2026 | An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access.... |
| CVE-2025-11729 | MEDIUM | 4.3 | — | Aug 19, 2026 | The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2025-9211 | MEDIUM | 6.7 | — | Aug 18, 2026 | Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 al... |
| CVE-2025-9210 | HIGH | 8.1 | — | Aug 18, 2026 | Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows ... |
| CVE-2025-27772 | HIGH | 7.4 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `... |
| CVE-2025-27771 | HIGH | 7.4 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `... |
| CVE-2025-27770 | HIGH | 7.4 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `... |
| CVE-2025-27621 | HIGH | 7.7 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U... |
| CVE-2025-10005 | MEDIUM | 4.3 | — | Aug 16, 2026 | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure ... |
| CVE-2025-7639 | HIGH | 7.1 | — | Aug 14, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now