2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-23165LOW3.7In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path...
CVE-2025-48219LOW3.5O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multim...
CVE-2025-4852LOW3.4A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue...
CVE-2025-4819LOW3.1A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of th...
CVE-2025-22233LOW3.1CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and fo...
CVE-2025-47929LOW2.1DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scr...
CVE-2025-47774LOW2.9Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, t...
CVE-2025-47285LOW2.9Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `...
CVE-2025-47279LOW3.1Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i...
CVE-2025-2570LOW2.7Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have...
CVE-2025-4762LOW2Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1....
CVE-2025-27525LOW3.9Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue a...
CVE-2025-32421LOW3.7Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-...
CVE-2025-0138LOW2Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet...
CVE-2025-0135LOW3.3An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ...
CVE-2025-0133LOW2.7A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Netw...
CVE-2025-20030LOW2.6Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge ...
CVE-2025-47278LOW1.8Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configura...
CVE-2025-40571LOW2.2A vulnerability has been identified in Mendix OIDC SSO (Mendix 10.12 compatible) (All versions < V4.0.1), Mendix OIDC SS...
CVE-2025-46748LOW2.7An authenticated user attempting to change their password could do so without using the current password.
CVE-2025-46744LOW2.7An authenticated administrator could modify the Created By username for a user account
CVE-2025-47274LOW2.4ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to...
CVE-2025-46718LOW3.3sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo ...
CVE-2025-46717LOW3.3sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very l...
CVE-2025-46729LOW2.1julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now