2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-2528LOW3.6Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authent...
CVE-2025-24808LOW3.1Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t...
CVE-2025-30222LOW2.1Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential envir...
CVE-2025-1452LOW3.5The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2025-0717LOW3.5To exploit the vulnerability, it is necessary:
CVE-2025-1203LOW3.5The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its...
CVE-2025-1062LOW3.5The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its...
CVE-2025-2588LOW3.3A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the f...
CVE-2025-27715LOW2.7Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channe...
CVE-2025-30344LOW3.7An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's respo...
CVE-2025-2574LOW2.1Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript functio...
CVE-2025-2555LOW2.9A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unkn...
CVE-2025-29923LOW3.7go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redi...
CVE-2025-30259LOW3.5The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protecti...
CVE-2025-30197LOW3.1Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing t...
CVE-2025-30235LOW3.5Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed...
CVE-2025-25040LOW3.3A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking...
CVE-2025-29431LOW3.2Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/departm...
CVE-2025-27512LOW2.1Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system u...
CVE-2025-25618LOW3.3Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and R...
CVE-2025-1398LOW3.3Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker wit...
CVE-2025-2341LOW3.1A vulnerability was found in IROAD Dash Cam X5 up to 20250203. It has been rated as problematic. This issue affects some...
CVE-2025-1624LOW3.5The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul...
CVE-2025-1623LOW3.5The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which coul...
CVE-2025-1622LOW3.5The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now