2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-58012LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Alex Content Mask content-mask allows Exploiting Incor...
CVE-2025-58009LOW3.8Missing Authorization vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Exploiting...
CVE-2025-10778LOW3.1A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /check...
CVE-2025-10776LOW3.7A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the co...
CVE-2025-10761LOW3.7A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the compon...
CVE-2025-59427LOW2.9The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the ...
CVE-2025-59692LOW3.7PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing ipta...
CVE-2025-59691LOW3.7PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon netwo...
CVE-2025-10650LOW1.8SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys und...
CVE-2025-59421LOW2.7Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2025-10671LOW3.7A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of t...
CVE-2025-30187LOW3.7In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries,...
CVE-2025-59410LOW3.7Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the s...
CVE-2025-59349LOW3.3Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses t...
CVE-2025-59414LOW3.1Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vul...
CVE-2025-59161LOW2.7Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11...
CVE-2025-59160LOW2.7Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insuf...
CVE-2025-30075LOW2.2In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the s...
CVE-2025-59270LOW3.1psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML au...
CVE-2025-26710LOW3.5There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control me...
CVE-2025-10316LOW2.3The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: befo...
CVE-2025-59453LOW3.2Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency acce...
CVE-2025-59437LOW3.2The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly catego...
CVE-2025-59436LOW3.2The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improp...
CVE-2025-43357LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now