2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59784HIGH7.22N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be incl...
CVE-2025-59783HIGH7.2API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al...
CVE-2025-12801MEDIUM6.5A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3...
CVE-2025-71238HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free ...
CVE-2025-70342MEDIUM6.6erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.jso...
CVE-2025-70341HIGH7.8Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
CVE-2025-40896MEDIUM4.8The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could per...
CVE-2025-40895MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on...
CVE-2025-40894MEDIUM5.4A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper valida...
CVE-2025-66168HIGH8.8WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  follow...
CVE-2025-70240CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.
CVE-2025-70239CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.
CVE-2025-70234CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.
CVE-2025-14480HIGH7.5IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-14456MEDIUM5.9IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1
CVE-2025-13688HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-13687HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-13686HIGH8.8IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands ...
CVE-2025-70241CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.
CVE-2025-70237CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.
CVE-2025-70236CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.
CVE-2025-66945CRITICAL9.1A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed...
CVE-2025-36364LOW3.3IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the ...
CVE-2025-36363HIGH7.5IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru...
CVE-2025-14923CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could prov...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now