2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12037 | MEDIUM | 4.4 | 0.2% | Feb 18, 2026 | The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2025-62183 | MEDIUM | 4.8 | 0.3% | Feb 17, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interf... |
| CVE-2025-13689 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to s... |
| CVE-2025-13333 | MEDIUM | 4.9 | 0.3% | Feb 17, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration o... |
| CVE-2025-36348 | MEDIUM | 4.9 | 0.3% | Feb 17, 2026 | IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, an... |
| CVE-2025-36183 | LOW | 2.7 | 0.2% | Feb 17, 2026 | IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e... |
| CVE-2025-33135 | MEDIUM | 6.1 | 0.2% | Feb 17, 2026 | IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim... |
| CVE-2025-33088 | HIGH | 7.4 | 0.1% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca... |
| CVE-2025-36379 | HIGH | 7.5 | 0.1% | Feb 17, 2026 | IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that... |
| CVE-2025-36377 | HIGH | 8.8 | 0.2% | Feb 17, 2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an... |
| CVE-2025-36376 | HIGH | 8.8 | 0.2% | Feb 17, 2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an... |
| CVE-2025-14289 | MEDIUM | 5.4 | 0.2% | Feb 17, 2026 | IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-13691 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ... |
| CVE-2025-70846 | HIGH | 7.1 | 0.2% | Feb 17, 2026 | lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field pass... |
| CVE-2025-67102 | HIGH | 7.6 | 0.2% | Feb 17, 2026 | A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to exec... |
| CVE-2025-36598 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di... |
| CVE-2025-36597 | MEDIUM | 4.7 | 0.3% | Feb 17, 2026 | Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di... |
| CVE-2025-36243 | MEDIUM | 4.3 | 0.1% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated att... |
| CVE-2025-33130 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras... |
| CVE-2025-33124 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to cras... |
| CVE-2025-33101 | MEDIUM | 5.9 | 0.2% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniqu... |
| CVE-2025-33089 | CRITICAL | 9.8 | 0.2% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac... |
| CVE-2025-32355 | HIGH | 7.9 | 1.2% | Feb 17, 2026 | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is ... |
| CVE-2025-27904 | MEDIUM | 6.5 | 0.1% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to... |
| CVE-2025-27903 | MEDIUM | 5.9 | 0.1% | Feb 17, 2026 | IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now