2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-49087LOW3.7In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to...
CVE-2025-7882LOW3.1A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue...
CVE-2025-7881LOW2.7A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vu...
CVE-2025-54314LOW2.8Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier becau...
CVE-2025-53901LOW3.5Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation ...
CVE-2025-7789LOW3.7A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the fu...
CVE-2025-6227LOW3.1Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al...
CVE-2025-7748LOW3.5A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon...
CVE-2025-7339LOW3.4on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0...
CVE-2025-53904LOW1.3The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` con...
CVE-2025-53840LOW2.4Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2...
CVE-2025-7703LOW3.1Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.
CVE-2025-52687LOW2.4Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point...
CVE-2025-53029LOW2.3Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2025-50104LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte...
CVE-2025-50100LOW2.2Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that ...
CVE-2025-50098LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-50081LOW3.1Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a...
CVE-2025-50066LOW2.7Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are...
CVE-2025-50065LOW3.7Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version...
CVE-2025-30752LOW3.7Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The suppo...
CVE-2025-30750LOW2.4Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-1...
CVE-2025-53903LOW1.3The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doe...
CVE-2025-7577LOW3.7A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problem...
CVE-2025-7569LOW3.5A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerab...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now