2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23415 | LOW | 3.1 | 0.1% | Feb 5, 2025 | An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t... |
| CVE-2025-0167 | LOW | 3.4 | 0.6% | Feb 5, 2025 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used fo... |
| CVE-2025-22601 | LOW | 3.1 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user ... |
| CVE-2025-0148 | LOW | 2.6 | 0.2% | Feb 3, 2025 | Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated us... |
| CVE-2025-24959 | LOW | 1 | 0.2% | Feb 3, 2025 | zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended... |
| CVE-2025-20643 | LOW | 3.9 | 0.1% | Feb 3, 2025 | In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo... |
| CVE-2025-24336 | LOW | 3.3 | 0.1% | Jan 31, 2025 | SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may b... |
| CVE-2025-24369 | LOW | 2.3 | 0.4% | Jan 27, 2025 | Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a pr... |
| CVE-2025-24145 | LOW | 3.3 | 0.2% | Jan 27, 2025 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and ... |
| CVE-2025-24141 | LOW | 3.3 | 0.2% | Jan 27, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. A... |
| CVE-2025-24121 | LOW | 3.3 | 0.2% | Jan 27, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS ... |
| CVE-2025-24100 | LOW | 3.3 | 0.2% | Jan 27, 2025 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, ... |
| CVE-2025-24034 | LOW | 3.2 | 0.2% | Jan 23, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Starting in version 0.7.0 and prior to ... |
| CVE-2025-0625 | LOW | 3.1 | 0.5% | Jan 22, 2025 | A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affect... |
| CVE-2025-21546 | LOW | 3.8 | 0.6% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions... |
| CVE-2025-21520 | LOW | 1.8 | 0.3% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff... |
| CVE-2025-0575 | LOW | 3.9 | 0.2% | Jan 19, 2025 | A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnera... |
| CVE-2025-23074 | LOW | 2.4 | 0.3% | Jan 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfi... |
| CVE-2025-23073 | LOW | 3.5 | 0.3% | Jan 14, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlock... |
| CVE-2025-21312 | LOW | 2.4 | 0.7% | Jan 14, 2025 | Windows Smart Card Reader Information Disclosure Vulnerability |
| CVE-2025-22151 | LOW | 3.7 | 0.4% | Jan 9, 2025 | Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type conf... |
| CVE-2025-22149 | LOW | 2.1 | 0.5% | Jan 9, 2025 | JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's ... |
| CVE-2025-22449 | LOW | 3.8 | 0.3% | Jan 9, 2025 | Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to... |
| CVE-2025-0245 | LOW | 3.3 | 0.3% | Jan 7, 2025 | Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now