2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-31199MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequo...
CVE-2025-31198MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1...
CVE-2025-31189HIGH8.2A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1...
CVE-2025-30466CRITICAL9.8This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4...
CVE-2025-5328HIGH8.8A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the functio...
CVE-2025-5327HIGH8.8A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of t...
CVE-2025-5326HIGH8.8A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as cr...
CVE-2025-5325CRITICAL9.8A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified ...
CVE-2025-4967CRITICAL9.1Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
CVE-2025-47933MEDIUM5.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, ...
CVE-2025-47288LOW3.5Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there...
CVE-2025-3050MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could ...
CVE-2025-2518HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is v...
CVE-2025-5324MEDIUM4.8A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function su...
CVE-2025-48336CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This ...
CVE-2025-46701HIGH7.3Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of ...
CVE-2025-32752MEDIUM4.6Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacke...
CVE-2025-5323MEDIUM6.3A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue af...
CVE-2025-46823HIGH8openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In ver...
CVE-2025-29632MEDIUM5.4Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP...
CVE-2025-48475HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch...
CVE-2025-46722HIGH7.3vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9....
CVE-2025-46570LOW2.6vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is p...
CVE-2025-48474HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec...
CVE-2025-48473MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation fro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now