2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-71422MEDIUM5.7Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume fe...
CVE-2025-14181MEDIUM6.5The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is und...
CVE-2025-14814MEDIUM6.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbo...
CVE-2025-32000MEDIUM4.3HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input...
CVE-2025-15696MEDIUM6.8The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rende...
CVE-2025-36084MEDIUM5.9IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-12767MEDIUM5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted reg...
CVE-2025-1280MEDIUM6.5The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive...
CVE-2025-14487MEDIUM5.3The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorizatio...
CVE-2025-14486MEDIUM5.3The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in...
CVE-2025-14484MEDIUM5.3The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization chec...
CVE-2025-71420MEDIUM4.3UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allow...
CVE-2025-71419MEDIUM5.4UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration...
CVE-2025-36421MEDIUM5.9IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an...
CVE-2025-36178MEDIUM5.4IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpu...
CVE-2025-36147MEDIUM6.1IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-...
CVE-2025-36076MEDIUM4.3IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source cod...
CVE-2025-36045MEDIUM4.3IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service d...
CVE-2025-33147MEDIUM5.9IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared networ...
CVE-2025-33141MEDIUM6.5IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information fr...
CVE-2025-1350MEDIUM5.3IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitiv...
CVE-2025-13882MEDIUM5.3IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM ...
CVE-2025-13533MEDIUM4.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an...
CVE-2025-56566MEDIUM4.6MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile ...
CVE-2025-36591MEDIUM4.4Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now