2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71422 | MEDIUM | 5.7 | — | Sep 27, 2026 | Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume fe... |
| CVE-2025-14181 | MEDIUM | 6.5 | — | Sep 25, 2026 | The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is und... |
| CVE-2025-14814 | MEDIUM | 6.4 | — | Sep 25, 2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbo... |
| CVE-2025-32000 | MEDIUM | 4.3 | — | Sep 24, 2026 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input... |
| CVE-2025-15696 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rende... |
| CVE-2025-36084 | MEDIUM | 5.9 | 0.2% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-12767 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted reg... |
| CVE-2025-1280 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive... |
| CVE-2025-14487 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorizatio... |
| CVE-2025-14486 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in... |
| CVE-2025-14484 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization chec... |
| CVE-2025-71420 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allow... |
| CVE-2025-71419 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration... |
| CVE-2025-36421 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an... |
| CVE-2025-36178 | MEDIUM | 5.4 | — | Sep 18, 2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpu... |
| CVE-2025-36147 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-... |
| CVE-2025-36076 | MEDIUM | 4.3 | — | Sep 18, 2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source cod... |
| CVE-2025-36045 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service d... |
| CVE-2025-33147 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared networ... |
| CVE-2025-33141 | MEDIUM | 6.5 | — | Sep 18, 2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information fr... |
| CVE-2025-1350 | MEDIUM | 5.3 | 0.4% | Sep 18, 2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitiv... |
| CVE-2025-13882 | MEDIUM | 5.3 | — | Sep 18, 2026 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM ... |
| CVE-2025-13533 | MEDIUM | 4.4 | — | Sep 18, 2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an... |
| CVE-2025-56566 | MEDIUM | 4.6 | 0.2% | Sep 16, 2026 | MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile ... |
| CVE-2025-36591 | MEDIUM | 4.4 | — | Sep 16, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now