2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-14186LOW3.5A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the f...
CVE-2025-66549LOW2.7Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside ...
CVE-2025-66515LOW2.7The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenti...
CVE-2025-66546LOW3.3Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly ...
CVE-2025-66479LOW1.8Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrar...
CVE-2025-12997LOW3.1Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with...
CVE-2025-20388LOW2.7In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-12954LOW2.7The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a spec...
CVE-2025-13640LOW3.5Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass aut...
CVE-2025-59700LOW3.9Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59696LOW3.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-65858LOW3.5A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript...
CVE-2025-13879LOW2.7Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with admin...
CVE-2025-58487LOW3.3Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity ...
CVE-2025-58483LOW3.3Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows loc...
CVE-2025-13805LOW3.7A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the ...
CVE-2025-13795LOW2.4A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c0...
CVE-2025-6666LOW2A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an ...
CVE-2025-66372LOW2.8Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
CVE-2025-58308LOW3.3Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi...
CVE-2025-13758LOW3.5Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, throu...
CVE-2025-66040LOW3.6Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vuln...
CVE-2025-65681LOW3.3An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers ...
CVE-2025-20373LOW2.7In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _in...
CVE-2025-55174LOW3.2In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now