2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-70330LOW3.3Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify...
CVE-2025-20073LOW1.8Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor...
CVE-2025-27769LOW2.6A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC...
CVE-2025-68467LOW3.4Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the...
CVE-2025-36364LOW3.3IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the ...
CVE-2025-12150LOW3.1A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf...
CVE-2025-15567LOW3.3Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
CVE-2025-67860LOW3.8A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller c...
CVE-2025-52603LOW3.5HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow ...
CVE-2025-14547LOW2.3An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs...
CVE-2025-14055LOW2.4An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special...
CVE-2025-14270LOW2.7The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, ...
CVE-2025-8860LOW3.3A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, t...
CVE-2025-36183LOW2.7IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e...
CVE-2025-14573LOW2.7Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team...
CVE-2025-69873LOW2.9ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the...
CVE-2025-14594LOW3.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and ...
CVE-2025-48509LOW1.8Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m...
CVE-2025-0029LOW1.8Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively ...
CVE-2025-33030LOW3.3Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an e...
CVE-2025-32739LOW2.8Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic...
CVE-2025-31648LOW3.9Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privileg...
CVE-2025-25058LOW3.3Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es...
CVE-2025-7432LOW1DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions.  This may allow an att...
CVE-2025-15320LOW3.3Tanium addressed a denial of service vulnerability in Tanium Client.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now