2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66249MEDIUM6.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue...
CVE-2025-60012MEDIUM6.3Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0...
CVE-2025-57849MEDIUM6.4A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being...
CVE-2025-36368HIGH7.2IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2....
CVE-2025-15515MEDIUM5.5The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific condit...
CVE-2025-14811MEDIUM5.9IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o...
CVE-2025-14504MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2025-14483MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2025-13779HIGH8.3Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW...
CVE-2025-13778HIGH7.1Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW...
CVE-2025-13777HIGH8.3Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW...
CVE-2025-13726HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke...
CVE-2025-13723HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o...
CVE-2025-13718HIGH7.5IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke...
CVE-2025-13702MEDIUM5.4IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site ...
CVE-2025-13337——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12455HIGH7.5Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.   The vulnerability co...
CVE-2025-12454MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ...
CVE-2025-12453MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ...
CVE-2025-70873HIGH7.5An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier al...
CVE-2025-70245CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.
CVE-2025-66955MEDIUM6.5Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated ...
CVE-2025-61154MEDIUM6.5Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau...
CVE-2025-13913MEDIUM6.8A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which...
CVE-2025-13462LOW3.3The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now