2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-4661LOW2.3A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain acces...
CVE-2025-1088LOW2.7In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to...
CVE-2025-49843LOW2.7conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2025-49824LOW1.7conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2025-45526LOW2.9A denial of service (DoS) vulnerability has been identified in the JavaScript library microlight version 0.0.7. This lib...
CVE-2025-45525LOW2.9A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a light...
CVE-2025-6199LOW3.3A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompressio...
CVE-2025-4754LOW2.3Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured...
CVE-2025-49842LOW1conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.2...
CVE-2025-6140LOW3.3A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped...
CVE-2025-6139LOW3.9A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issu...
CVE-2025-6170LOW2.5A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inpu...
CVE-2025-24388LOW3.8A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due t...
CVE-2025-6107LOW3.1A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the funct...
CVE-2025-21085LOW2.1PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory ut...
CVE-2025-49597LOW3.9handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export libr...
CVE-2025-49583LOW3.5XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code....
CVE-2025-48825LOW2.5RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may al...
CVE-2025-4227LOW3.5An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/g...
CVE-2025-1699LOW2.8An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauth...
CVE-2025-1698LOW2.8Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker...
CVE-2025-5991LOW2.1There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/...
CVE-2025-47096LOW3.5Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2025-36576LOW2.7Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high...
CVE-2025-42990LOW3Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, wi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now