2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-23288LOW3.3NVIDIA GPU Display Driver for Windows contains a vulnerability  where an attacker may cause an exposure of sensitive sys...
CVE-2025-23287LOW3.3NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level infor...
CVE-2025-54781LOW2.8Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelbla...
CVE-2025-6011LOW3.7A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish ...
CVE-2025-37109LOW3.5Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-37108LOW3.5Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-51385LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.
CVE-2025-51384LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
CVE-2025-51383LOW3.5D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
CVE-2025-54085LOW3.8CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers ...
CVE-2025-49082LOW2.7CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers ...
CVE-2025-53113LOW2.7GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-8283LOW3.7A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman se...
CVE-2025-8225LOW3.3A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_de...
CVE-2025-8205LOW3.7A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by ...
CVE-2025-8204LOW3.7A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerabilit...
CVE-2025-43712LOW2.9JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipst...
CVE-2025-54568LOW3.7Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate...
CVE-2025-0253LOW2.4HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configu...
CVE-2025-7001LOW2.7An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18....
CVE-2025-46686LOW3.5Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated ...
CVE-2025-4878LOW3.6A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f...
CVE-2025-52580LOW2.4Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploi...
CVE-2025-44657LOW3.9In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file...
CVE-2025-54352LOW3.7WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now