2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-53535LOW2.1Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the origin...
CVE-2025-3777LOW3.5Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image...
CVE-2025-53177LOW3.9Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may...
CVE-2025-53176LOW3.3Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil...
CVE-2025-53175LOW3.3Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil...
CVE-2025-53174LOW3.3Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil...
CVE-2025-53172LOW3.3Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil...
CVE-2025-53171LOW3.3Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil...
CVE-2025-7080LOW3.7A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080...
CVE-2025-7061LOW2.7A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerabilit...
CVE-2025-49005LOW3.7Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3....
CVE-2025-0885LOW1.8Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2025-6942LOW3.8The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri...
CVE-2025-53492LOW3.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-24335LOW2Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, wh...
CVE-2025-24334LOW3.3The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release vers...
CVE-2025-52463LOW3.1Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerab...
CVE-2025-4654LOW3.7The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au...
CVE-2025-6932LOW3.7A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the functi...
CVE-2025-40710LOW2.3Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when a...
CVE-2025-6817LOW3.3A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C...
CVE-2025-6816LOW3.3A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_...
CVE-2025-52992LOW3.2The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow a...
CVE-2025-52991LOW3.2The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writa...
CVE-2025-46416LOW2.9The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now