2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-46570LOW2.6vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is p...
CVE-2025-3913LOW3.8Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly validate pe...
CVE-2025-27706LOW3.4CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to ver...
CVE-2025-3864LOW2.3Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote a...
CVE-2025-47295LOW3.7A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 th...
CVE-2025-46777LOW2.7A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,...
CVE-2025-24473LOW3.7A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindow...
CVE-2025-2826LOW2.6n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 st...
CVE-2025-48370LOW2.7auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserByI...
CVE-2025-2236LOW2.1Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentica...
CVE-2025-46804LOW3.3A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information...
CVE-2025-5179LOW3.4A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by ...
CVE-2025-5138LOW3.5A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability...
CVE-2025-48376LOW2.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-48708LOW3.3gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for ...
CVE-2025-48064LOW3.3GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3,...
CVE-2025-5031LOW3.1A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some u...
CVE-2025-48009LOW3.1Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single ...
CVE-2025-1421LOW2.4Data provided in a request performed to the server while activating a new device are put in a database. Other high privi...
CVE-2025-1420LOW2.4Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-p...
CVE-2025-1419LOW2.4Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perfo...
CVE-2025-48015LOW3.7Failed login response could be different depending on whether the username was local or central.
CVE-2025-47938LOW3.8TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51...
CVE-2025-4945LOW3.7A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software....
CVE-2025-31185LOW3.3A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now