2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61970 | LOW | 1 | — | Aug 11, 2026 | Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ... |
| CVE-2025-48505 | LOW | 1 | — | Aug 11, 2026 | Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ... |
| CVE-2025-15680 | LOW | 2.4 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph... |
| CVE-2025-15674 | LOW | 2.7 | 0.2% | Aug 6, 2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ... |
| CVE-2025-14779 | LOW | 3.8 | 0.2% | Aug 6, 2026 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet... |
| CVE-2025-13736 | LOW | 3.7 | 0.2% | Aug 6, 2026 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo... |
| CVE-2025-12627 | LOW | 2.4 | 0.1% | Aug 6, 2026 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated... |
| CVE-2025-15677 | LOW | 3.5 | 0.2% | Aug 5, 2026 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin... |
| CVE-2025-71402 | LOW | 2 | 0.2% | Aug 1, 2026 | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou... |
| CVE-2025-14562 | LOW | 3.1 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2025-71396 | LOW | 2.3 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em... |
| CVE-2025-71394 | LOW | 2.3 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut... |
| CVE-2025-59866 | LOW | 3.3 | — | Jul 17, 2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es... |
| CVE-2025-8412 | LOW | 2 | 0.1% | Jul 14, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa... |
| CVE-2025-15668 | LOW | 3.3 | 0.1% | Jul 6, 2026 | A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/i... |
| CVE-2025-15667 | LOW | 3.3 | — | Jul 6, 2026 | A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit... |
| CVE-2025-0824 | LOW | 3.7 | 0.1% | Jun 29, 2026 | Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue... |
| CVE-2025-15619 | LOW | 3.5 | 0.1% | Jun 23, 2026 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin... |
| CVE-2025-59382 | LOW | 1.2 | 0.3% | Jun 10, 2026 | QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version: |
| CVE-2025-12656 | LOW | 3.8 | 0.3% | Jun 6, 2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de... |
| CVE-2025-62338 | LOW | 3.3 | 0.1% | Jun 4, 2026 | HCL BigFix Cloud Lifecycle Management is affected by lack of input validation. This low-level flaw allows unauthorized ... |
| CVE-2025-48616 | LOW | 3.3 | 0.1% | Jun 1, 2026 | In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning... |
| CVE-2025-68711 | LOW | 2.4 | 0.2% | May 26, 2026 | AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker... |
| CVE-2025-68708 | LOW | 2.4 | 0.2% | May 26, 2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the ... |
| CVE-2025-68710 | LOW | 2.4 | 0.2% | May 26, 2026 | Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now