2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-32026LOW3.8Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to ve...
CVE-2025-20941LOW3.3Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of speci...
CVE-2025-3360LOW3.7A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp...
CVE-2025-3329LOW3.1A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affect...
CVE-2025-32054LOW3.3In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
CVE-2025-3160LOW3.3A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerabili...
CVE-2025-29991LOW2.2Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It u...
CVE-2025-3154LOW2.1Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictio...
CVE-2025-27608LOW1Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vu...
CVE-2025-30469LOW2.4This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person wi...
CVE-2025-24193LOW2.4This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with...
CVE-2025-30369LOW2.7Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed t...
CVE-2025-30368LOW2.7Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricte...
CVE-2025-27149LOW2.7Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data exp...
CVE-2025-1217LOW3.1In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http ...
CVE-2025-2923LOW3.3A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the...
CVE-2025-2922LOW2A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unk...
CVE-2025-2920LOW2A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown ...
CVE-2025-2914LOW3.3A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Sri...
CVE-2025-30371LOW2.1Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and ...
CVE-2025-27726LOW2.1Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process...
CVE-2025-27574LOW3.6Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and e...
CVE-2025-30877LOW2.7Missing Authorization vulnerability in fatcatapps Quiz Cat quiz-cat allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-20233LOW3.3In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Pyth...
CVE-2025-31160LOW2.9atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or po...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now