2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70342 | MEDIUM | 6.6 | 0.2% | Mar 4, 2026 | erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.jso... |
| CVE-2025-70341 | HIGH | 7.8 | 0.2% | Mar 4, 2026 | Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files. |
| CVE-2025-40896 | MEDIUM | 4.8 | 0.1% | Mar 4, 2026 | The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could per... |
| CVE-2025-40895 | MEDIUM | 4.8 | 0.2% | Mar 4, 2026 | A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on... |
| CVE-2025-40894 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper valida... |
| CVE-2025-66168 | HIGH | 8.8 | 0.8% | Mar 4, 2026 | WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the follow... |
| CVE-2025-70240 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51. |
| CVE-2025-70239 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55. |
| CVE-2025-70234 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS. |
| CVE-2025-14480 | HIGH | 7.5 | 0.2% | Mar 3, 2026 | IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-14456 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1 |
| CVE-2025-13688 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ... |
| CVE-2025-13687 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ... |
| CVE-2025-13686 | HIGH | 8.8 | 0.3% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ... |
| CVE-2025-70241 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5. |
| CVE-2025-70237 | CRITICAL | 9.8 | 0.7% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr. |
| CVE-2025-70236 | CRITICAL | 9.8 | 0.6% | Mar 3, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter. |
| CVE-2025-66945 | CRITICAL | 9.1 | 0.5% | Mar 3, 2026 | A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed... |
| CVE-2025-36364 | LOW | 3.3 | 0.1% | Mar 3, 2026 | IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the ... |
| CVE-2025-36363 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru... |
| CVE-2025-14923 | CRITICAL | 9.8 | 0.2% | Mar 3, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could prov... |
| CVE-2025-14604 | HIGH | 7.8 | 0.1% | Mar 3, 2026 | IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow... |
| CVE-2025-13734 | MEDIUM | 5.4 | 0.1% | Mar 3, 2026 | IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data ... |
| CVE-2025-13616 | HIGH | 7.5 | 0.2% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ... |
| CVE-2025-13490 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now