2025 CVE Vulnerabilities

45,124 CVEs published in 2025.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2025-61970LOW1Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ...
CVE-2025-48505LOW1Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ...
CVE-2025-15680LOW2.4TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph...
CVE-2025-15674LOW2.7The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ...
CVE-2025-14779LOW3.8The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet...
CVE-2025-13736LOW3.7When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo...
CVE-2025-12627LOW2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated...
CVE-2025-15677LOW3.5The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin...
CVE-2025-71402LOW2better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou...
CVE-2025-14562LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2025-71396LOW2.3SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em...
CVE-2025-71394LOW2.3SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut...
CVE-2025-59866LOW3.3The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es...
CVE-2025-8412LOW2A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa...
CVE-2025-15668LOW3.3A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/i...
CVE-2025-15667LOW3.3A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit...
CVE-2025-0824LOW3.7Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue...
CVE-2025-15619LOW3.5HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin...
CVE-2025-59382LOW1.2QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
CVE-2025-12656LOW3.8The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de...
CVE-2025-62338LOW3.3HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized ...
CVE-2025-48616LOW3.3In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning...
CVE-2025-68711LOW2.4AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker...
CVE-2025-68708LOW2.4SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the ...
CVE-2025-68710LOW2.4Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now