2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43419 | HIGH | 8.8 | 0.3% | Nov 4, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tah... |
| CVE-2025-43413 | HIGH | 7.5 | 0.5% | Nov 4, 2025 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, mac... |
| CVE-2025-43407 | HIGH | 7.8 | 0.2% | Nov 4, 2025 | This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and i... |
| CVE-2025-43405 | HIGH | 7.5 | 0.5% | Nov 4, 2025 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, mac... |
| CVE-2025-43401 | HIGH | 7.5 | 0.9% | Nov 4, 2025 | A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Son... |
| CVE-2025-43399 | HIGH | 7.5 | 0.5% | Nov 4, 2025 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS ... |
| CVE-2025-43387 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe... |
| CVE-2025-43386 | HIGH | 7.8 | 0.2% | Nov 4, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS ... |
| CVE-2025-43376 | HIGH | 7.5 | 0.7% | Nov 4, 2025 | A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7... |
| CVE-2025-43373 | HIGH | 7.5 | 0.4% | Nov 4, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,... |
| CVE-2025-43364 | HIGH | 7.8 | 0.2% | Nov 4, 2025 | A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8,... |
| CVE-2025-43361 | HIGH | 7.8 | 0.2% | Nov 4, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Se... |
| CVE-2025-43338 | HIGH | 7.1 | 0.2% | Nov 4, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, ... |
| CVE-2025-43323 | HIGH | 8.1 | 0.3% | Nov 4, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26... |
| CVE-2025-46556 | HIGH | 7.5 | 0.3% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently ... |
| CVE-2025-34501 | HIGH | 7 | 0.2% | Nov 3, 2025 | Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple... |
| CVE-2025-50735 | HIGH | 7.5 | 0.8% | Nov 3, 2025 | Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot ... |
| CVE-2025-63441 | HIGH | 7.3 | 0.2% | Nov 3, 2025 | Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u... |
| CVE-2025-60785 | HIGH | 8.8 | 0.6% | Nov 3, 2025 | A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attac... |
| CVE-2025-60503 | HIGH | 8.7 | 0.3% | Nov 3, 2025 | A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 whe... |
| CVE-2025-36093 | HIGH | 7.4 | 0.2% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content ... |
| CVE-2025-11761 | HIGH | 7.8 | 0.2% | Nov 3, 2025 | A potential security vulnerability has been identified in the HP Client Management Script Library software, which might ... |
| CVE-2025-48397 | HIGH | 7.1 | 0.2% | Nov 3, 2025 | The privileged user could log in without sufficient credentials after enabling an application protocol. This security is... |
| CVE-2025-48396 | HIGH | 8.3 | 0.3% | Nov 3, 2025 | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This sec... |
| CVE-2025-12503 | HIGH | 7.1 | 0.3% | Nov 3, 2025 | EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now