2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-3637LOW3.1A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CS...
CVE-2025-3635LOW3.5A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log ...
CVE-2025-25046LOW3.7IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via URL or query parame...
CVE-2025-46394LOW3.3In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal esc...
CVE-2025-23253LOW2.5NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit...
CVE-2025-27907LOW2.7IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an auth...
CVE-2025-3850LOW2.7A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issu...
CVE-2025-2517LOW2.3Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
CVE-2025-43916LOW3.4Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use...
CVE-2025-32408LOW2.5In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.
CVE-2025-3840LOW2.1An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer co...
CVE-2025-25228LOW3.8A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu...
CVE-2025-43903LOW3.3NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting...
CVE-2025-3795LOW3.4A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown fun...
CVE-2025-25985LOW2.6An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim...
CVE-2025-25983LOW3.4An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64...
CVE-2025-1525LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-1524LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-1523LOW3.5The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could all...
CVE-2025-32789LOW3.7EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei...
CVE-2025-32787LOW3.1SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerab...
CVE-2025-27538LOW2.7Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when ...
CVE-2025-32435LOW2.6Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could poten...
CVE-2025-30731LOW3.6Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration)....
CVE-2025-30703LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now