2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-61924LOW3.8PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and...
CVE-2025-11851LOW3.5A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set...
CVE-2025-54499LOW3.7Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp...
CVE-2025-62380LOW2.9mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr...
CVE-2025-62379LOW3.1Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e...
CVE-2025-2529LOW3.7Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u...
CVE-2025-6026LOW3.1An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all...
CVE-2025-56746LOW2.2Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli...
CVE-2025-59280LOW3.1Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
CVE-2025-55695LOW3.3Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
CVE-2025-62366LOW2.9mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr...
CVE-2025-8594LOW3.8The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a...
CVE-2025-11731LOW3.1A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty...
CVE-2025-42909LOW3SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p...
CVE-2025-62174LOW3.5Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2...
CVE-2025-31995LOW3.5HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities ...
CVE-2025-11645LOW2.4A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown...
CVE-2025-11637LOW3.7A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component ...
CVE-2025-2139LOW3.5IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ...
CVE-2025-2138LOW3.5IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the netw...
CVE-2025-8606LOW2.4The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less ...
CVE-2025-52655LOW3.1Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part...
CVE-2025-21057LOW3.3Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to...
CVE-2025-21046LOW2.4Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to tem...
CVE-2025-4614LOW2.7An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now