2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55652MEDIUM5.5A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers t...
CVE-2025-55650MEDIUM5.5A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacker...
CVE-2025-55649MEDIUM5.5A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attack...
CVE-2025-55648MEDIUM5.5A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows...
CVE-2025-55647MEDIUM5.5An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to c...
CVE-2025-55645MEDIUM5.5A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to ...
CVE-2025-55644MEDIUM5.5A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacker...
CVE-2025-55643MEDIUM5.5A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attacke...
CVE-2025-55642MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_writ...
CVE-2025-55641MEDIUM5.5A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows a...
CVE-2025-15659MEDIUM6.5Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.
CVE-2025-15658MEDIUM5.9Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.
CVE-2025-64215MEDIUM6.5Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co...
CVE-2025-15546MEDIUM5.4The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy s...
CVE-2025-7019MEDIUM5.5Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Servi...
CVE-2025-7018MEDIUM5.5Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Den...
CVE-2025-7010MEDIUM5.5Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malformed PDF file may all...
CVE-2025-7006MEDIUM5.5Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Deni...
CVE-2025-7005MEDIUM5.5Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Se...
CVE-2025-46313MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ...
CVE-2025-46308MEDIUM5.3An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, ma...
CVE-2025-46293MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab...
CVE-2025-43339MEDIUM5.5An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious...
CVE-2025-43278MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab...
CVE-2025-30459MEDIUM5.5A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now