2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-47555LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ...
CVE-2025-12738LOW1.3Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by...
CVE-2025-14083LOW2.7A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, pot...
CVE-2025-36411LOW3.5IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2025-15535LOW3.3A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in t...
CVE-2025-61873LOW2.6Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV expor...
CVE-2025-31186LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to...
CVE-2025-24090LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ...
CVE-2025-14058LOW3.2A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us...
CVE-2025-67685LOW3.8A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4,...
CVE-2025-58409LOW3.5Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to ...
CVE-2025-15506LOW3.3A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertT...
CVE-2025-15505LOW2.4A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web...
CVE-2025-53470LOW3.1Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memo...
CVE-2025-62487LOW3.5On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor...
CVE-2025-3950LOW3.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1...
CVE-2025-15224LOW3.1When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly s...
CVE-2025-62224LOW3.5User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacke...
CVE-2025-31963LOW3.3Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2...
CVE-2025-12958LOW2.7The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i...
CVE-2025-9543LOW3.5The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w...
CVE-2025-15454LOW3.1A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file sr...
CVE-2025-62840LOW3.3A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Ba...
CVE-2025-69412LOW3.4KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phi...
CVE-2025-11964LOW1.9On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that U...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now