2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68429 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present ... |
| CVE-2025-68401 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/... |
| CVE-2025-68399 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting... |
| CVE-2025-68275 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnera... |
| CVE-2025-67876 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in Church... |
| CVE-2025-67875 | MEDIUM | 5.4 | 0.2% | Dec 17, 2025 | ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to ... |
| CVE-2025-67794 | MEDIUM | 6.1 | 0.1% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and fi... |
| CVE-2025-67789 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users... |
| CVE-2025-59849 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lo... |
| CVE-2025-55254 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.032... |
| CVE-2025-46292 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26... |
| CVE-2025-46288 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS T... |
| CVE-2025-46283 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, ... |
| CVE-2025-46282 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app... |
| CVE-2025-46278 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to... |
| CVE-2025-43541 | MEDIUM | 4.3 | 34.1% | Dec 17, 2025 | A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iP... |
| CVE-2025-43536 | MEDIUM | 4.3 | 0.5% | Dec 17, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and... |
| CVE-2025-43535 | MEDIUM | 4.3 | 0.8% | Dec 17, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,... |
| CVE-2025-43533 | MEDIUM | 5.7 | 0.3% | Dec 17, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-43514 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to... |
| CVE-2025-43501 | MEDIUM | 4.3 | 0.8% | Dec 17, 2025 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and ... |
| CVE-2025-43475 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may ... |
| CVE-2025-14764 | MEDIUM | 5.3 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the... |
| CVE-2025-14763 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to t... |
| CVE-2025-14762 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to intr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now