2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-50422LOW2.9Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f...
CVE-2025-8515LOW3.7A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1...
CVE-2025-54956LOW3.2The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header f...
CVE-2025-8506LOW3.5A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problema...
CVE-2025-23290LOW2.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics whi...
CVE-2025-23288LOW3.3NVIDIA GPU Display Driver for Windows contains a vulnerability  where an attacker may cause an exposure of sensitive sys...
CVE-2025-23287LOW3.3NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level infor...
CVE-2025-54781LOW2.8Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelbla...
CVE-2025-6011LOW3.7A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish ...
CVE-2025-37109LOW3.5Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-37108LOW3.5Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-51385LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.
CVE-2025-51384LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
CVE-2025-51383LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
CVE-2025-54085LOW3.8CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers ...
CVE-2025-49082LOW2.7CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers ...
CVE-2025-53113LOW2.7GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-8283LOW3.7A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman se...
CVE-2025-8225LOW3.3A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_de...
CVE-2025-8205LOW3.7A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by ...
CVE-2025-8204LOW3.7A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerabilit...
CVE-2025-43712LOW2.9JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipst...
CVE-2025-54568LOW3.7Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate...
CVE-2025-0253LOW2.4HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configu...
CVE-2025-7001LOW2.7An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now