2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14604HIGH7.8IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow...
CVE-2025-13734MEDIUM5.4IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data ...
CVE-2025-13616HIGH7.5IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ...
CVE-2025-13490MEDIUM5.9IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0....
CVE-2025-69765HIGH7.5Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus...
CVE-2025-67840HIGH7.2Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil...
CVE-2025-63912HIGH7.5Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da...
CVE-2025-63911HIGH7.2Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti...
CVE-2025-63910HIGH7.2An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al...
CVE-2025-63909HIGH7.8Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4....
CVE-2025-15599MEDIUM6.1DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers...
CVE-2025-62817HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ...
CVE-2025-62816MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4...
CVE-2025-66680HIGH7.1An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele...
CVE-2025-66363HIGH7.5An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit...
CVE-2025-62815MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference ...
CVE-2025-62814HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ...
CVE-2025-70821CRITICAL9.8renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
CVE-2025-64736HIGH7.1An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma...
CVE-2025-57622CRITICAL9.8An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ...
CVE-2025-52365HIGH7.8A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ...
CVE-2025-59060MEDIUM5.3Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. ...
CVE-2025-59059CRITICAL9.8Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ...
CVE-2025-15598MEDIUM5.9A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend...
CVE-2025-15595HIGH7.8Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now