2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43194 | CRITICAL | 9.8 | 0.7% | Jul 30, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Vent... |
| CVE-2025-43193 | CRITICAL | 9.8 | 0.7% | Jul 30, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, m... |
| CVE-2025-43192 | CRITICAL | 9.8 | 0.6% | Jul 30, 2025 | A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonom... |
| CVE-2025-43189 | CRITICAL | 9.8 | 0.7% | Jul 30, 2025 | This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. ... |
| CVE-2025-43186 | CRITICAL | 9.8 | 1.1% | Jul 30, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15... |
| CVE-2025-43184 | CRITICAL | 9.8 | 0.6% | Jul 30, 2025 | This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, mac... |
| CVE-2025-31281 | CRITICAL | 9.1 | 1.1% | Jul 30, 2025 | An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, ... |
| CVE-2025-31279 | CRITICAL | 9.8 | 0.9% | Jul 30, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6... |
| CVE-2025-31229 | CRITICAL | 9.1 | 0.7% | Jul 30, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read ... |
| CVE-2025-54381 | CRITICAL | 9.9 | 11.1% | Jul 29, 2025 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1... |
| CVE-2025-40600 | CRITICAL | 9.8 | 0.8% | Jul 29, 2025 | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticate... |
| CVE-2025-53102 | CRITICAL | 9.8 | 0.4% | Jul 29, 2025 | Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5... |
| CVE-2025-44136 | CRITICAL | 9.8 | 2.4% | Jul 29, 2025 | MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e... |
| CVE-2025-50738 | CRITICAL | 9.8 | 2.0% | Jul 29, 2025 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us... |
| CVE-2025-46059 | CRITICAL | 9.8 | 0.7% | Jul 29, 2025 | langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component.... |
| CVE-2025-7458 | CRITICAL | 9.1 | 0.2% | Jul 29, 2025 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attack... |
| CVE-2025-40682 | CRITICAL | 9.8 | 0.3% | Jul 29, 2025 | SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, creat... |
| CVE-2025-53082 | CRITICAL | 9.1 | 0.4% | Jul 29, 2025 | An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unin... |
| CVE-2025-53081 | CRITICAL | 9.1 | 0.4% | Jul 29, 2025 | An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in uninte... |
| CVE-2025-8264 | CRITICAL | 9 | 0.4% | Jul 29, 2025 | Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in... |
| CVE-2025-53078 | CRITICAL | 9.8 | 0.4% | Jul 29, 2025 | Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via ... |
| CVE-2025-54428 | CRITICAL | 9.8 | 0.5% | Jul 28, 2025 | RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessibl... |
| CVE-2025-54426 | CRITICAL | 9.9 | 0.3% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f... |
| CVE-2025-54419 | CRITICAL | 10 | 0.4% | Jul 28, 2025 | A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t... |
| CVE-2025-54299 | CRITICAL | 9.4 | 0.4% | Jul 28, 2025 | A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now