2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-15497LOW3.8Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigge...
CVE-2025-9615LOW3.3A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. Ne...
CVE-2025-57784LOW3.3Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows...
CVE-2025-71148LOW3.3In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure...
CVE-2025-47555LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ...
CVE-2025-12738LOW1.3Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by...
CVE-2025-14083LOW2.7A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot...
CVE-2025-36411LOW3.5IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2025-15535LOW3.3A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in t...
CVE-2025-61873LOW2.6Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor...
CVE-2025-31186LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to...
CVE-2025-24090LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ...
CVE-2025-14058LOW3.2A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us...
CVE-2025-67685LOW3.8A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4,...
CVE-2025-58409LOW3.5Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to ...
CVE-2025-15506LOW3.3A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT...
CVE-2025-15505LOW2.4A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web...
CVE-2025-53470LOW3.1Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo...
CVE-2025-62487LOW3.5On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor...
CVE-2025-3950LOW3.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1...
CVE-2025-15224LOW3.1When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s...
CVE-2025-62224LOW3.5User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke...
CVE-2025-31963LOW3.3Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2...
CVE-2025-12958LOW2.7The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i...
CVE-2025-9543LOW3.5The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now