2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-27400LOW2.9Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2025-22274LOW2It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page....
CVE-2025-22272LOW2.1In the "/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg" endpoint, it is possible to inject code in the "modalDlgMsgIn...
CVE-2025-0914LOW3.8An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users ...
CVE-2025-0759LOW3.3IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared reso...
CVE-2025-26698LOW2.7Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, maliciou...
CVE-2025-0760LOW2.7A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials du...
CVE-2025-22211LOW3.4A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attacke...
CVE-2025-25878LOW3.8A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ...
CVE-2025-25877LOW3.8A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ...
CVE-2025-25299LOW2.3CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Sit...
CVE-2025-24806LOW2.3Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2025-25300LOW1.3smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner ...
CVE-2025-25899LOW3.5A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'gw' parameter at /userRpm/WanDynamicIp...
CVE-2025-0692LOW3.5The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, whi...
CVE-2025-1207LOW3.1A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unkn...
CVE-2025-1243LOW2The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when th...
CVE-2025-24432LOW3.7Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-chec...
CVE-2025-24430LOW3.7Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-chec...
CVE-2025-24429LOW3.5Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Ac...
CVE-2025-21337LOW3.3Windows NTFS Elevation of Privilege Vulnerability
CVE-2025-1180LOW3.1A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_...
CVE-2025-23191LOW3.1Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host heade...
CVE-2025-1152LOW3.7A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the f...
CVE-2025-1151LOW3.1A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now