2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0036 | LOW | 3.2 | 0.1% | Jun 10, 2025 | In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic oper... |
| CVE-2025-5889 | LOW | 3.1 | 0.4% | Jun 9, 2025 | A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problemat... |
| CVE-2025-5864 | LOW | 3.7 | 0.4% | Jun 9, 2025 | A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnera... |
| CVE-2025-5648 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_i... |
| CVE-2025-5647 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability was found in Radare2 5.9.9 and classified as problematic. This issue affects the function r_cons_context... |
| CVE-2025-5646 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r... |
| CVE-2025-5645 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_i... |
| CVE-2025-5644 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the fun... |
| CVE-2025-5643 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function con... |
| CVE-2025-5642 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in t... |
| CVE-2025-5641 | LOW | 2.5 | 0.2% | Jun 5, 2025 | A vulnerability was found in Radare2 5.9.9. It has been rated as problematic. This issue affects the function r_cons_is_... |
| CVE-2025-20985 | LOW | 3.3 | 0.1% | Jun 4, 2025 | Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse... |
| CVE-2025-5508 | LOW | 3.4 | 0.3% | Jun 3, 2025 | A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this i... |
| CVE-2025-49112 | LOW | 3.1 | 0.2% | Jun 2, 2025 | setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used. |
| CVE-2025-48946 | LOW | 3.7 | 0.2% | May 30, 2025 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. libo... |
| CVE-2025-1792 | LOW | 3.1 | 0.2% | May 30, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for g... |
| CVE-2025-48480 | LOW | 2.7 | 0.3% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the admi... |
| CVE-2025-48479 | LOW | 2.7 | 0.3% | May 30, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager ... |
| CVE-2025-48491 | LOW | 2.7 | 0.5% | May 30, 2025 | Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in... |
| CVE-2025-47288 | LOW | 3.5 | 0.2% | May 29, 2025 | Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there... |
| CVE-2025-46570 | LOW | 2.6 | 0.2% | May 29, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is p... |
| CVE-2025-3913 | LOW | 3.8 | 0.3% | May 29, 2025 | Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate pe... |
| CVE-2025-27706 | LOW | 3.4 | 0.2% | May 28, 2025 | CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to ver... |
| CVE-2025-3864 | LOW | 2.3 | 0.7% | May 28, 2025 | Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote a... |
| CVE-2025-47295 | LOW | 3.7 | 0.6% | May 28, 2025 | A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now