2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-23415LOW3.1An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t...
CVE-2025-0167LOW3.4When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used fo...
CVE-2025-22601LOW3.1Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user ...
CVE-2025-0148LOW2.6Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated us...
CVE-2025-24959LOW1zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended...
CVE-2025-20643LOW3.9In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo...
CVE-2025-24336LOW3.3SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may b...
CVE-2025-24369LOW2.3Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a pr...
CVE-2025-24145LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and ...
CVE-2025-24141LOW3.3An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. A...
CVE-2025-24121LOW3.3A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS ...
CVE-2025-24100LOW3.3A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, ...
CVE-2025-24034LOW3.2Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to ...
CVE-2025-0625LOW3.1A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affect...
CVE-2025-21546LOW3.8Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions...
CVE-2025-21520LOW1.8Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff...
CVE-2025-0575LOW3.9A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnera...
CVE-2025-23074LOW2.4Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfi...
CVE-2025-23073LOW3.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlock...
CVE-2025-21312LOW2.4Windows Smart Card Reader Information Disclosure Vulnerability
CVE-2025-22151LOW3.7Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type conf...
CVE-2025-22149LOW2.1JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's ...
CVE-2025-22449LOW3.8Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to...
CVE-2025-0245LOW3.3Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now