2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-49549LOW2.7Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author...
CVE-2025-52889LOW3.4Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus vers...
CVE-2025-4656LOW3.1Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontroll...
CVE-2025-52884LOW1.7RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repos...
CVE-2025-52570LOW1.7Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. I...
CVE-2025-48463LOW3.1Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on ...
CVE-2025-6536LOW3.3A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is...
CVE-2025-6527LOW3.1A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown fun...
CVE-2025-6524LOW3.1A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the...
CVE-2025-6509LOW3.5A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been decl...
CVE-2025-4563LOW2.7A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation au...
CVE-2025-52968LOW2.7xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (Fo...
CVE-2025-52937LOW2Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with p...
CVE-2025-6497LOW3.3A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function p...
CVE-2025-52926LOW2.7In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface...
CVE-2025-6496LOW3.3A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the...
CVE-2025-6494LOW3.3A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as ...
CVE-2025-6490LOW3.3A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problemat...
CVE-2025-52916LOW2.2Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).
CVE-2025-6401LOW3.5A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an...
CVE-2025-6217LOW2.5PEAK-System Driver PCANFD_ADD_FILTERS Time-Of-Check Time-Of-Use Information Disclosure Vulnerability. This vulnerability...
CVE-2025-52484LOW2.7RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constrai...
CVE-2025-48059LOW2.7PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criter...
CVE-2025-5416LOW2.7A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it require...
CVE-2025-47293LOW2.7PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now