2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-21851LOW3.3In the Linux kernel, the following vulnerability has been resolved: bpf: Fix softlockup in arena_map_free on 64k page k...
CVE-2025-24912LOW3.7hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentic...
CVE-2025-0900LOW3.3PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows r...
CVE-2025-27398LOW2.7A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do ...
CVE-2025-27432LOW2.4The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certai...
CVE-2025-27430LOW3.5Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with ...
CVE-2025-26655LOW3.1SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to es...
CVE-2025-26865LOW3.5Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects...
CVE-2025-25615LOW2.7Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sectio...
CVE-2025-2149LOW2.5A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the functi...
CVE-2025-2119LOW2A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been declared as problematic. This vu...
CVE-2025-1363LOW3.5The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an...
CVE-2025-27839LOW3.2operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet...
CVE-2025-2093LOW3.1A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affec...
CVE-2025-22212LOW2.7A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticate...
CVE-2025-1953LOW2.6A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an ...
CVE-2025-1939LOW3.9Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could h...
CVE-2025-1878LOW3.1A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability a...
CVE-2025-0895LOW2.4IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive i...
CVE-2025-1795LOW2.3During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded t...
CVE-2025-27400LOW2.9Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2025-22274LOW2It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page....
CVE-2025-22272LOW2.1In the "/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg" endpoint, it is possible to inject code in the "modalDlgMsgIn...
CVE-2025-0914LOW3.8An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users ...
CVE-2025-0759LOW3.3IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared reso...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now