2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67789 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users... |
| CVE-2025-59849 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lo... |
| CVE-2025-55254 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.032... |
| CVE-2025-46292 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26... |
| CVE-2025-46288 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS T... |
| CVE-2025-46283 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An a... |
| CVE-2025-46282 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app... |
| CVE-2025-46278 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to... |
| CVE-2025-43541 | MEDIUM | 4.3 | 32.0% | Dec 17, 2025 | A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iP... |
| CVE-2025-43536 | MEDIUM | 4.3 | 0.5% | Dec 17, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and... |
| CVE-2025-43535 | MEDIUM | 4.3 | 0.8% | Dec 17, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,... |
| CVE-2025-43533 | MEDIUM | 5.7 | 0.3% | Dec 17, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-43514 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to... |
| CVE-2025-43501 | MEDIUM | 4.3 | 0.7% | Dec 17, 2025 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and ... |
| CVE-2025-43475 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may ... |
| CVE-2025-14764 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the... |
| CVE-2025-14763 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to t... |
| CVE-2025-14762 | MEDIUM | 6 | 0.2% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to intr... |
| CVE-2025-14761 | MEDIUM | 6 | 0.2% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-67074 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-65233 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ... |
| CVE-2025-34440 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire... |
| CVE-2025-34439 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet... |
| CVE-2025-34435 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated... |
| CVE-2025-14760 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now