2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52182HIGH7.5The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.
CVE-2025-62306MEDIUM5HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a...
CVE-2025-62300MEDIUM5.9HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can...
CVE-2025-62299MEDIUM6.6HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces...
CVE-2025-62307MEDIUM5.4HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, ...
CVE-2025-53999MEDIUM6.5Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
CVE-2025-15689CRITICAL9.8Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVE-2025-15688CRITICAL9.3Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVE-2025-15637HIGH8.1Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
CVE-2025-14601HIGH8.6An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execu...
CVE-2025-14602MEDIUM5.3The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a...
CVE-2025-36398MEDIUM5.4IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe...
CVE-2025-36255HIGH8.8IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe...
CVE-2025-36254HIGH7.4IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attac...
CVE-2025-14603HIGH8.8The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable ...
CVE-2025-14600CRITICAL9.3An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access....
CVE-2025-11729MEDIUM4.3The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc...
CVE-2025-9211MEDIUM6.7Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 al...
CVE-2025-9210HIGH8.1Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows ...
CVE-2025-27772HIGH7.4UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `...
CVE-2025-27771HIGH7.4UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `...
CVE-2025-27770HIGH7.4UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `...
CVE-2025-27621HIGH7.7UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U...
CVE-2025-10005MEDIUM4.3The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure ...
CVE-2025-7639HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now