2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-47929LOW2.1DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scr...
CVE-2025-47774LOW2.9Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, t...
CVE-2025-47285LOW2.9Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `...
CVE-2025-47279LOW3.1Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i...
CVE-2025-2570LOW2.7Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have...
CVE-2025-4762LOW2Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1....
CVE-2025-27525LOW3.9Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue a...
CVE-2025-32421LOW3.7Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-...
CVE-2025-0138LOW2Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are delet...
CVE-2025-0135LOW3.3An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ...
CVE-2025-0133LOW2.7A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Netw...
CVE-2025-20030LOW2.6Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge ...
CVE-2025-47278LOW1.8Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configura...
CVE-2025-40571LOW2.2A vulnerability has been identified in Mendix OIDC SSO (Mendix 10.12 compatible) (All versions < V4.0.1), Mendix OIDC SS...
CVE-2025-46748LOW2.7An authenticated user attempting to change their password could do so without using the current password.
CVE-2025-46744LOW2.7An authenticated administrator could modify the Created By username for a user account
CVE-2025-47274LOW2.4ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to...
CVE-2025-46718LOW3.3sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo ...
CVE-2025-46717LOW3.3sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very l...
CVE-2025-46729LOW2.1julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web the...
CVE-2025-4537LOW3.1A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue i...
CVE-2025-47736LOW2.9dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not v...
CVE-2025-46812LOW2Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to...
CVE-2025-46712LOW3.7Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-...
CVE-2025-44021LOW2.8OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now