2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-13584LOW3.5A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the com...
CVE-2025-54515LOW1The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State ...
CVE-2025-11934LOW2.7Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier ...
CVE-2025-31216LOW2.4The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke...
CVE-2025-66062LOW3.4URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allo...
CVE-2025-64299LOW2.7LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' passwor...
CVE-2025-52666LOW2.7Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions cau...
CVE-2025-13425LOW1.9A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice wh...
CVE-2025-11884LOW2.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uC...
CVE-2025-64757LOW3.5Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm...
CVE-2025-65014LOW3.7LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password ...
CVE-2025-12119LOW3.3A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13083LOW3.7Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrec...
CVE-2025-12761LOW3.5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple mult...
CVE-2025-55074LOW3.5Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which ...
CVE-2025-64734LOW2.4Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access...
CVE-2025-12792LOW3.2The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A loc...
CVE-2025-63292LOW3.5Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x...
CVE-2025-65083LOW3.2GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be prob...
CVE-2025-13232LOW3.5A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Do...
CVE-2025-6945LOW3.5GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5...
CVE-2025-11990LOW3.5GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that ...
CVE-2025-54560LOW3.8A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0...
CVE-2025-54559LOW3.7An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote ...
CVE-2025-54342LOW3.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now