2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67789MEDIUM5.3An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users...
CVE-2025-59849MEDIUM6.1Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lo...
CVE-2025-55254MEDIUM4.8Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.032...
CVE-2025-46292MEDIUM5.5This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26...
CVE-2025-46288MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS T...
CVE-2025-46283MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An a...
CVE-2025-46282MEDIUM5.5The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app...
CVE-2025-46278MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to...
CVE-2025-43541MEDIUM4.3A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iP...
CVE-2025-43536MEDIUM4.3A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and...
CVE-2025-43535MEDIUM4.3The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,...
CVE-2025-43533MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-43514MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to...
CVE-2025-43501MEDIUM4.3A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and ...
CVE-2025-43475MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may ...
CVE-2025-14764MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the...
CVE-2025-14763MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to t...
CVE-2025-14762MEDIUM6Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to intr...
CVE-2025-14761MEDIUM6Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to intro...
CVE-2025-67074MEDIUM6.5A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-65233MEDIUM6.1Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ...
CVE-2025-34440MEDIUM6.1AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire...
CVE-2025-34439MEDIUM6.1AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet...
CVE-2025-34435MEDIUM6.5AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated...
CVE-2025-14760MEDIUM6Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now