2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-62316LOW2.3HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured...
CVE-2025-62312LOW3HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho...
CVE-2025-62309LOW2.6HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may ...
CVE-2025-31959LOW3.5HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co...
CVE-2025-62345LOW2.7HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component con...
CVE-2025-54505LOW2A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa...
CVE-2025-9957LOW2.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-15632LOW3.5A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat....
CVE-2025-43236LOW3.3A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son...
CVE-2025-62184LOW3.4Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf...
CVE-2025-7741LOW2.1Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user ...
CVE-2025-14684LOW3.3IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject dat...
CVE-2025-14808LOW3.1IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from...
CVE-2025-11571LOW2.1Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm...
CVE-2025-31703LOW2.4A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may g...
CVE-2025-31966LOW2.7HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, th...
CVE-2025-69239LOW2.7Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker...
CVE-2025-26474LOW3.3in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can...
CVE-2025-13462LOW3.3The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi...
CVE-2025-62328LOW3.7HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by defa...
CVE-2025-70082LOW2.7The administrator password can be changed without knowledge of the current password. When chained with an authentication...
CVE-2025-70330LOW3.3Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modify...
CVE-2025-20073LOW1.8Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor...
CVE-2025-27769LOW2.6A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC...
CVE-2025-68467LOW3.4Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now