2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-46826LOW1.3insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's ...
CVE-2025-46824LOW3.1The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacke...
CVE-2025-46551LOW3.7JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL versio...
CVE-2025-20977LOW3.3Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows loc...
CVE-2025-20960LOW3.3Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attacker...
CVE-2025-1400LOW3.1Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers...
CVE-2025-1399LOW3.1Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buff...
CVE-2025-46735LOW1.1Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue ...
CVE-2025-2545LOW2.3Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptograp...
CVE-2025-4215LOW3.7A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is t...
CVE-2025-47226LOW3.3Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
CVE-2025-3514LOW3.5The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h...
CVE-2025-3513LOW3.5The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow h...
CVE-2025-32971LOW3.8XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4,...
CVE-2025-3301LOW1DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on al...
CVE-2025-46330LOW3.3libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat...
CVE-2025-46329LOW3.3libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to...
CVE-2025-46614LOW3.3In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a...
CVE-2025-23377LOW3.4Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output ...
CVE-2025-32471LOW3.7The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.
CVE-2025-0627LOW3.5The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of i...
CVE-2025-3995LOW3.4A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vuln...
CVE-2025-3994LOW3.4A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unkn...
CVE-2025-46656LOW3.3python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>...
CVE-2025-46653LOW3.1Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now