2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-6275LOW3.3A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulner...
CVE-2025-6274LOW3.3A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the funct...
CVE-2025-6273LOW3.3A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the functio...
CVE-2025-6272LOW3.3A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function Mar...
CVE-2025-6271LOW3.3A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_c...
CVE-2025-4661LOW2.3A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain acces...
CVE-2025-1088LOW2.7In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to...
CVE-2025-49843LOW2.7conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2025-49824LOW1.7conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2025-45526LOW2.9A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This lib...
CVE-2025-45525LOW2.9A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a light...
CVE-2025-6199LOW3.3A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompressio...
CVE-2025-4754LOW2.3Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This v...
CVE-2025-49842LOW1conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.2...
CVE-2025-6140LOW3.3A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped...
CVE-2025-6139LOW3.9A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issu...
CVE-2025-6170LOW2.5A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inpu...
CVE-2025-24388LOW3.8A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due t...
CVE-2025-6107LOW3.1A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the funct...
CVE-2025-21085LOW2.1PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory ut...
CVE-2025-49597LOW3.9handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export libr...
CVE-2025-49583LOW3.5XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code....
CVE-2025-48825LOW2.5RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al...
CVE-2025-4227LOW3.5An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g...
CVE-2025-1699LOW2.8An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now