2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-46686LOW3.5Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated ...
CVE-2025-4878LOW3.6A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f...
CVE-2025-52580LOW2.4Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploi...
CVE-2025-44657LOW3.9In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file...
CVE-2025-54352LOW3.7WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC...
CVE-2025-49087LOW3.7In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to...
CVE-2025-7882LOW3.1A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue...
CVE-2025-7881LOW2.7A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vu...
CVE-2025-54314LOW2.8Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier becau...
CVE-2025-53901LOW3.5Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation ...
CVE-2025-7789LOW3.7A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the fu...
CVE-2025-6227LOW3.1Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al...
CVE-2025-7748LOW3.5A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon...
CVE-2025-7339LOW3.4on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0...
CVE-2025-53904LOW1.3The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` con...
CVE-2025-53840LOW2.4Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2...
CVE-2025-7703LOW3.1Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.
CVE-2025-52687LOW2.4Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point...
CVE-2025-53029LOW2.3Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2025-50104LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte...
CVE-2025-50100LOW2.2Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that ...
CVE-2025-50098LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-50081LOW3.1Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a...
CVE-2025-50066LOW2.7Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are...
CVE-2025-50065LOW3.7Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now