2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14604 | HIGH | 7.8 | 0.1% | Mar 3, 2026 | IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow... |
| CVE-2025-13734 | MEDIUM | 5.4 | 0.1% | Mar 3, 2026 | IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data ... |
| CVE-2025-13616 | HIGH | 7.5 | 0.2% | Mar 3, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ... |
| CVE-2025-13490 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.... |
| CVE-2025-69765 | HIGH | 7.5 | 0.7% | Mar 3, 2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus... |
| CVE-2025-67840 | HIGH | 7.2 | 3.7% | Mar 3, 2026 | Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil... |
| CVE-2025-63912 | HIGH | 7.5 | 0.1% | Mar 3, 2026 | Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da... |
| CVE-2025-63911 | HIGH | 7.2 | 2.3% | Mar 3, 2026 | Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti... |
| CVE-2025-63910 | HIGH | 7.2 | 0.4% | Mar 3, 2026 | An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al... |
| CVE-2025-63909 | HIGH | 7.8 | 0.3% | Mar 3, 2026 | Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.... |
| CVE-2025-15599 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers... |
| CVE-2025-62817 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer ... |
| CVE-2025-62816 | MEDIUM | 5.5 | 0.1% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4... |
| CVE-2025-66680 | HIGH | 7.1 | 0.2% | Mar 3, 2026 | An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to dele... |
| CVE-2025-66363 | HIGH | 7.5 | 0.5% | Mar 3, 2026 | An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit... |
| CVE-2025-62815 | MEDIUM | 5.5 | 0.1% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference ... |
| CVE-2025-62814 | HIGH | 7.5 | 0.5% | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference ... |
| CVE-2025-70821 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component |
| CVE-2025-64736 | HIGH | 7.1 | 0.2% | Mar 3, 2026 | An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Ma... |
| CVE-2025-57622 | CRITICAL | 9.8 | 0.5% | Mar 3, 2026 | An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature ... |
| CVE-2025-52365 | HIGH | 7.8 | 0.5% | Mar 3, 2026 | A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to ... |
| CVE-2025-59060 | MEDIUM | 5.3 | 0.3% | Mar 3, 2026 | Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. ... |
| CVE-2025-59059 | CRITICAL | 9.8 | 1.2% | Mar 3, 2026 | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users ... |
| CVE-2025-15598 | MEDIUM | 5.9 | 0.2% | Mar 3, 2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend... |
| CVE-2025-15595 | HIGH | 7.8 | 0.1% | Mar 3, 2026 | Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now