2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1150 | LOW | 3.1 | 0.6% | Feb 10, 2025 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the func... |
| CVE-2025-1149 | LOW | 3.1 | 0.5% | Feb 10, 2025 | A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup... |
| CVE-2025-1148 | LOW | 3.1 | 0.6% | Feb 10, 2025 | A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function lin... |
| CVE-2025-25183 | LOW | 2.6 | 0.2% | Feb 7, 2025 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements... |
| CVE-2025-1081 | LOW | 3.1 | 0.3% | Feb 6, 2025 | A vulnerability was found in Bharti Airtel Xstream Fiber up to 20250123. It has been rated as problematic. This issue af... |
| CVE-2025-23415 | LOW | 3.1 | 0.1% | Feb 5, 2025 | An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t... |
| CVE-2025-0167 | LOW | 3.4 | 0.6% | Feb 5, 2025 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used fo... |
| CVE-2025-22601 | LOW | 3.1 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user ... |
| CVE-2025-0148 | LOW | 2.6 | 0.2% | Feb 3, 2025 | Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated us... |
| CVE-2025-24959 | LOW | 1 | 0.2% | Feb 3, 2025 | zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended... |
| CVE-2025-20643 | LOW | 3.9 | 0.1% | Feb 3, 2025 | In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo... |
| CVE-2025-24336 | LOW | 3.3 | 0.1% | Jan 31, 2025 | SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may b... |
| CVE-2025-24369 | LOW | 2.3 | 0.4% | Jan 27, 2025 | Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a pr... |
| CVE-2025-24145 | LOW | 3.3 | 0.2% | Jan 27, 2025 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and ... |
| CVE-2025-24141 | LOW | 3.3 | 0.2% | Jan 27, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. A... |
| CVE-2025-24121 | LOW | 3.3 | 0.2% | Jan 27, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS ... |
| CVE-2025-24100 | LOW | 3.3 | 0.2% | Jan 27, 2025 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, ... |
| CVE-2025-24034 | LOW | 3.2 | 0.2% | Jan 23, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to ... |
| CVE-2025-0625 | LOW | 3.1 | 0.5% | Jan 22, 2025 | A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affect... |
| CVE-2025-21546 | LOW | 3.8 | 0.6% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions... |
| CVE-2025-21520 | LOW | 1.8 | 0.3% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff... |
| CVE-2025-0575 | LOW | 3.9 | 0.2% | Jan 19, 2025 | A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnera... |
| CVE-2025-23074 | LOW | 2.4 | 0.3% | Jan 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfi... |
| CVE-2025-23073 | LOW | 3.5 | 0.3% | Jan 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlock... |
| CVE-2025-21312 | LOW | 2.4 | 0.7% | Jan 14, 2025 | Windows Smart Card Reader Information Disclosure Vulnerability |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now