2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-68585LOW2.7Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrec...
CVE-2025-57840LOW2.2ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect...
CVE-2025-14408LOW3.3Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2025-61738LOW2.3Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network...
CVE-2025-15005LOW3.7A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.exam...
CVE-2025-12654LOW2.7The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory cr...
CVE-2025-14955LOW3.7A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_...
CVE-2025-14882LOW3.8An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intende...
CVE-2025-14881LOW3.8Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not ...
CVE-2025-65046LOW3.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-68469LOW3.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14...
CVE-2025-68462LOW3.2Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump f...
CVE-2025-14841LOW3.3A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHand...
CVE-2025-14836LOW2.7A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_sa...
CVE-2025-46279LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS...
CVE-2025-46277LOW3.3A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe...
CVE-2025-43531LOW3.1A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 1...
CVE-2025-13326LOW3.9Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged f...
CVE-2025-13324LOW3.7Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite to...
CVE-2025-13321LOW3.3Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on ser...
CVE-2025-65185LOW2.8There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enume...
CVE-2025-14266LOW0.6CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administ...
CVE-2025-13352LOW3Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identit...
CVE-2025-68164LOW2.7In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
CVE-2025-68162LOW2.7In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now