2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-65942LOW2.7VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1....
CVE-2025-33200LOW3.3NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-33199LOW3.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow b...
CVE-2025-33198LOW3.3NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-13596LOW2.7A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Applicati...
CVE-2025-13584LOW3.5A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the com...
CVE-2025-54515LOW1The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State ...
CVE-2025-11934LOW2.7Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier ...
CVE-2025-31216LOW2.4The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke...
CVE-2025-66062LOW3.4URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allo...
CVE-2025-64299LOW2.7LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' passwor...
CVE-2025-52666LOW2.7Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions cau...
CVE-2025-13425LOW1.9A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice wh...
CVE-2025-11884LOW2.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uC...
CVE-2025-64757LOW3.5Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm...
CVE-2025-65014LOW3.7LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password ...
CVE-2025-12119LOW3.3A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13083LOW3.7Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrec...
CVE-2025-12761LOW3.5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple mult...
CVE-2025-55074LOW3.5Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which ...
CVE-2025-64734LOW2.4Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access...
CVE-2025-12792LOW3.2The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A loc...
CVE-2025-63292LOW3.5Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x...
CVE-2025-65083LOW3.2GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be prob...
CVE-2025-13232LOW3.5A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Do...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now