2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-54086LOW3.3CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to vers...
CVE-2025-58769LOW3.3auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import...
CVE-2025-43718LOW2.9Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within t...
CVE-2025-56675LOW3.5The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers wi...
CVE-2025-23291LOW2.4NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause...
CVE-2025-11195LOW3.3Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can...
CVE-2025-59163LOW2.1vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding a...
CVE-2025-55795LOW3.5The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership v...
CVE-2025-11137LOW3.5A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File...
CVE-2025-11134LOW2.4A security vulnerability has been detected in Cudy TR1200 1.16.3-20230804-164635. Impacted is an unknown function of the...
CVE-2025-10173LOW2.7The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable ...
CVE-2025-60019LOW3.7glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memo...
CVE-2025-36857LOW3.3Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's conf...
CVE-2025-10949LOW2.4A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of...
CVE-2025-59422LOW3.1Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /con...
CVE-2025-10909LOW2.4A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the f...
CVE-2025-23346LOW3.3NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereferen...
CVE-2025-23340LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b...
CVE-2025-23271LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b...
CVE-2025-23255LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-...
CVE-2025-23248LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b...
CVE-2025-0672LOW3.8An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user...
CVE-2025-8282LOW3.5The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the pag...
CVE-2025-10823LOW3.3A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c...
CVE-2025-59526LOW2.7mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now