2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-62654LOW2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62653LOW2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62505LOW3LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-...
CVE-2025-60361LOW3.3radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
CVE-2025-11896LOW2.1In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stac...
CVE-2025-61924LOW3.8PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and...
CVE-2025-11851LOW3.5A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set...
CVE-2025-54499LOW3.7Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp...
CVE-2025-62380LOW2.9mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr...
CVE-2025-62379LOW3.1Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e...
CVE-2025-2529LOW3.7Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u...
CVE-2025-6026LOW3.1An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all...
CVE-2025-56746LOW2.2Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli...
CVE-2025-59280LOW3.1Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
CVE-2025-55695LOW3.3Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
CVE-2025-62366LOW2.9mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr...
CVE-2025-8594LOW3.8The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a...
CVE-2025-11731LOW3.1A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty...
CVE-2025-42909LOW3SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p...
CVE-2025-62174LOW3.5Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2...
CVE-2025-39964LOW3.3In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a...
CVE-2025-31995LOW3.5HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities ...
CVE-2025-11645LOW2.4A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown...
CVE-2025-11637LOW3.7A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component ...
CVE-2025-2139LOW3.5IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now