2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-71424LOW3.5Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and includi...
CVE-2025-1218LOW3.4The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough b...
CVE-2025-15698LOW3.5The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could ...
CVE-2025-13166LOW3.7The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered us...
CVE-2025-26790LOW3.7Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memo...
CVE-2025-64031LOW2.5libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field...
CVE-2025-70820LOW3.5Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
CVE-2025-64059LOW1.8Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is ...
CVE-2025-45480LOW3Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
CVE-2025-15695LOW3.5The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the ...
CVE-2025-52657LOW3.5HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the...
CVE-2025-52652LOW3.5HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content,...
CVE-2025-52651LOW3.5HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause u...
CVE-2025-15614LOW3.3ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z arc...
CVE-2025-15694LOW3.5The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before output...
CVE-2025-15693LOW2.7The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its admini...
CVE-2025-15692LOW3.5The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting ...
CVE-2025-62343LOW3.1HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sess...
CVE-2025-62341LOW3.7HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo...
CVE-2025-62318LOW3.7HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages...
CVE-2025-62315LOW3.4HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validatio...
CVE-2025-9486LOW3.3GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2...
CVE-2025-61970LOW1Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ...
CVE-2025-48505LOW1Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ...
CVE-2025-15680LOW2.4TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now