2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-55307LOW3.3An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF ...
CVE-2025-12734LOW3.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 1...
CVE-2025-67646LOW3.5TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do...
CVE-2025-5467LOW3.3It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files ...
CVE-2025-67639LOW3.5A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers...
CVE-2025-13127LOW3.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Informa...
CVE-2025-14082LOW2.7A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information dis...
CVE-2025-67500LOW3.7Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro...
CVE-2025-67499LOW3.6The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versi...
CVE-2025-64787LOW3.3Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by...
CVE-2025-64786LOW3.3Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by...
CVE-2025-59923LOW2.7An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ...
CVE-2025-57823LOW2.7A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticato...
CVE-2025-64255LOW2.7Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting ...
CVE-2025-64254LOW2.7Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured A...
CVE-2025-40818LOW3.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications con...
CVE-2025-36102LOW2.7IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user t...
CVE-2025-65228LOW3.5A stored cross-site scripting vulnerability exists in the web management interface of the R.V.R. Elettronica TLK302T tel...
CVE-2025-60912LOW3.3phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The gene...
CVE-2025-14228LOW3.5A weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local...
CVE-2025-14186LOW3.5A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the f...
CVE-2025-66549LOW2.7Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside ...
CVE-2025-66515LOW2.7The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenti...
CVE-2025-66546LOW3.3Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly ...
CVE-2025-66479LOW1.8Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now