2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6275 | LOW | 3.3 | 0.2% | Jun 19, 2025 | A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulner... |
| CVE-2025-6274 | LOW | 3.3 | 0.2% | Jun 19, 2025 | A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the funct... |
| CVE-2025-6273 | LOW | 3.3 | 0.2% | Jun 19, 2025 | A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the functio... |
| CVE-2025-6272 | LOW | 3.3 | 0.2% | Jun 19, 2025 | A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function Mar... |
| CVE-2025-6271 | LOW | 3.3 | 0.2% | Jun 19, 2025 | A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_c... |
| CVE-2025-4661 | LOW | 2.3 | 0.2% | Jun 19, 2025 | A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain acces... |
| CVE-2025-1088 | LOW | 2.7 | 0.4% | Jun 18, 2025 | In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to... |
| CVE-2025-49843 | LOW | 2.7 | 0.5% | Jun 17, 2025 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2025-49824 | LOW | 1.7 | 0.2% | Jun 17, 2025 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2025-45526 | LOW | 2.9 | 0.1% | Jun 17, 2025 | A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This lib... |
| CVE-2025-45525 | LOW | 2.9 | 0.1% | Jun 17, 2025 | A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a light... |
| CVE-2025-6199 | LOW | 3.3 | 0.1% | Jun 17, 2025 | A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompressio... |
| CVE-2025-4754 | LOW | 2.3 | 0.4% | Jun 17, 2025 | Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This v... |
| CVE-2025-49842 | LOW | 1 | 0.2% | Jun 17, 2025 | conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.2... |
| CVE-2025-6140 | LOW | 3.3 | 0.2% | Jun 16, 2025 | A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped... |
| CVE-2025-6139 | LOW | 3.9 | 0.3% | Jun 16, 2025 | A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issu... |
| CVE-2025-6170 | LOW | 2.5 | 0.2% | Jun 16, 2025 | A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inpu... |
| CVE-2025-24388 | LOW | 3.8 | 0.2% | Jun 16, 2025 | A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due t... |
| CVE-2025-6107 | LOW | 3.1 | 0.4% | Jun 16, 2025 | A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the funct... |
| CVE-2025-21085 | LOW | 2.1 | 0.3% | Jun 15, 2025 | PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory ut... |
| CVE-2025-49597 | LOW | 3.9 | 0.2% | Jun 13, 2025 | handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export libr... |
| CVE-2025-49583 | LOW | 3.5 | 0.2% | Jun 13, 2025 | XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.... |
| CVE-2025-48825 | LOW | 2.5 | 0.1% | Jun 13, 2025 | RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al... |
| CVE-2025-4227 | LOW | 3.5 | 0.1% | Jun 13, 2025 | An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g... |
| CVE-2025-1699 | LOW | 2.8 | 0.1% | Jun 11, 2025 | An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now