2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-36364LOW3.3IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the ...
CVE-2025-12150LOW3.1A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf...
CVE-2025-15567LOW3.3Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
CVE-2025-67860LOW3.8A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller c...
CVE-2025-52603LOW3.5HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow ...
CVE-2025-14547LOW2.3An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs...
CVE-2025-14055LOW2.4An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special...
CVE-2025-14270LOW2.7The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, ...
CVE-2025-8860LOW3.3A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, t...
CVE-2025-36183LOW2.7IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e...
CVE-2025-14573LOW2.7Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team...
CVE-2025-69873LOW2.9ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the...
CVE-2025-14594LOW3.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and ...
CVE-2025-48509LOW1.8Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m...
CVE-2025-0029LOW1.8Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively ...
CVE-2025-33030LOW3.3Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an e...
CVE-2025-32739LOW2.8Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic...
CVE-2025-31648LOW3.9Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privileg...
CVE-2025-25058LOW3.3Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es...
CVE-2025-7432LOW1DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions.  This may allow an att...
CVE-2025-15320LOW3.3Tanium addressed a denial of service vulnerability in Tanium Client.
CVE-2025-68458LOW3.7Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTT...
CVE-2025-68157LOW3.7Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTT...
CVE-2025-15323LOW3.7Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
CVE-2025-15321LOW2.7Tanium addressed an improper input validation vulnerability in Tanium Appliance.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now