2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-0627LOW3.5The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of i...
CVE-2025-3995LOW3.4A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vuln...
CVE-2025-3994LOW3.4A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unkn...
CVE-2025-46656LOW3.3python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>...
CVE-2025-46653LOW3.1Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un...
CVE-2025-3637LOW3.1A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CS...
CVE-2025-3635LOW3.5A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log ...
CVE-2025-25046LOW3.7IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via URL or query parame...
CVE-2025-46394LOW3.3In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal esc...
CVE-2025-23253LOW2.5NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit...
CVE-2025-27907LOW2.7IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an auth...
CVE-2025-3850LOW2.7A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issu...
CVE-2025-2517LOW2.3Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
CVE-2025-43916LOW3.4Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use...
CVE-2025-32408LOW2.5In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.
CVE-2025-3840LOW2.1An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer co...
CVE-2025-25228LOW3.8A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu...
CVE-2025-43903LOW3.3NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting...
CVE-2025-3795LOW3.4A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2025-25985LOW2.6An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim...
CVE-2025-25983LOW3.4An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64...
CVE-2025-1525LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-1524LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-1523LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-32789LOW3.7EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now