2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-36228LOW3.8IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API...
CVE-2025-52598LOW3.7Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-15095LOW3.5A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the f...
CVE-2025-15084LOW3.1A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService....
CVE-2025-68585LOW2.7Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrec...
CVE-2025-57840LOW2.2ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect...
CVE-2025-14408LOW3.3Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2025-61738LOW2.3Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network...
CVE-2025-15005LOW3.7A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.exam...
CVE-2025-12654LOW2.7The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory cr...
CVE-2025-14955LOW3.7A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_...
CVE-2025-14882LOW3.8An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intende...
CVE-2025-14881LOW3.8Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not ...
CVE-2025-65046LOW3.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-68469LOW3.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14...
CVE-2025-68462LOW3.2Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump f...
CVE-2025-14841LOW3.3A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHand...
CVE-2025-14836LOW2.7A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_sa...
CVE-2025-46279LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS...
CVE-2025-46277LOW3.3A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe...
CVE-2025-43531LOW3.1A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 1...
CVE-2025-13326LOW3.9Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged f...
CVE-2025-13324LOW3.7Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to...
CVE-2025-13321LOW3.3Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser...
CVE-2025-65185LOW2.8There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enume...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now