2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12037MEDIUM4.4The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2025-62183MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interf...
CVE-2025-13689HIGH8.8IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to s...
CVE-2025-13333MEDIUM4.9IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration o...
CVE-2025-36348MEDIUM4.9IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, an...
CVE-2025-36183LOW2.7IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e...
CVE-2025-33135MEDIUM6.1IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim...
CVE-2025-33088HIGH7.4IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca...
CVE-2025-36379HIGH7.5IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that...
CVE-2025-36377HIGH8.8IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an...
CVE-2025-36376HIGH8.8IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an...
CVE-2025-14289MEDIUM5.4IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-13691MEDIUM6.5IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ...
CVE-2025-70846HIGH7.1lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field pass...
CVE-2025-67102HIGH7.6A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to exec...
CVE-2025-36598MEDIUM6.5Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di...
CVE-2025-36597MEDIUM4.7Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di...
CVE-2025-36243MEDIUM4.3IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated att...
CVE-2025-33130MEDIUM6.5IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras...
CVE-2025-33124MEDIUM6.5IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras...
CVE-2025-33101MEDIUM5.9IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniqu...
CVE-2025-33089CRITICAL9.8IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac...
CVE-2025-32355HIGH7.9Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is ...
CVE-2025-27904MEDIUM6.5IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to...
CVE-2025-27903MEDIUM5.9IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now