2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-41000LOW2.1Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits...
CVE-2025-9821LOW2.7SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, t...
CVE-2025-58272LOW3.7Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views ...
CVE-2025-21040LOW3.3Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attacker...
CVE-2025-21039LOW3.3Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local...
CVE-2025-21038LOW3.3Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows loca...
CVE-2025-21029LOW3.3Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send...
CVE-2025-21026LOW3.3Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to int...
CVE-2025-7039LOW3.7A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, al...
CVE-2025-8298LOW3.8Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure Vulne...
CVE-2025-9797LOW2.4A vulnerability was determined in mrvautin expressCart up to b31302f4e99c3293bd742c6d076a721e168118b0. This impacts an u...
CVE-2025-58160LOW2.3tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior ...
CVE-2025-9071LOW2.3Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG...
CVE-2025-43255LOW3.3An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sono...
CVE-2025-48979LOW3.4An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileg...
CVE-2025-9591LOW2.4A security vulnerability has been detected in ZrLog up to 3.1.5. This vulnerability affects unknown code of the file /ap...
CVE-2025-9590LOW3.5A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerabil...
CVE-2025-9589LOW2.5A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/...
CVE-2025-51643LOW2.4Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentic...
CVE-2025-9514LOW3.7A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registr...
CVE-2025-25733LOW3.5Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829...
CVE-2025-8447LOW3.1An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to an...
CVE-2025-9416LOW2.4A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file...
CVE-2025-3456LOW3.8On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in...
CVE-2025-9401LOW3.7A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now