2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43349 | LOW | 2.8 | 0.5% | Sep 15, 2025 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7 and iPadOS 18... |
| CVE-2025-43344 | LOW | 3.3 | 0.3% | Sep 15, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, ... |
| CVE-2025-43328 | LOW | 3.3 | 0.2% | Sep 15, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl... |
| CVE-2025-43301 | LOW | 3.3 | 0.2% | Sep 15, 2025 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2025-43294 | LOW | 3.3 | 0.2% | Sep 15, 2025 | An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue... |
| CVE-2025-43283 | LOW | 3.3 | 0.4% | Sep 15, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be ... |
| CVE-2025-59399 | LOW | 3.1 | 0.2% | Sep 15, 2025 | libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error me... |
| CVE-2025-59398 | LOW | 3.1 | 0.2% | Sep 15, 2025 | The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 2... |
| CVE-2025-36082 | LOW | 3.3 | 0.1% | Sep 15, 2025 | IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system. |
| CVE-2025-10434 | LOW | 2.4 | 0.2% | Sep 15, 2025 | A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a... |
| CVE-2025-10423 | LOW | 3.7 | 0.4% | Sep 15, 2025 | A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The... |
| CVE-2025-0164 | LOW | 2.3 | 0.1% | Sep 14, 2025 | IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unautho... |
| CVE-2025-10388 | LOW | 3.5 | 0.2% | Sep 14, 2025 | A vulnerability was identified in Selleo Mentingo 2025.08.27. This issue affects some unknown processing of the file /ap... |
| CVE-2025-10340 | LOW | 3.5 | 0.2% | Sep 13, 2025 | A vulnerability was determined in WhatCD Gazelle up to 63b337026d49b5cf63ce4be20fdabdc880112fa3. The affected element is... |
| CVE-2025-4234 | LOW | 2.4 | 0.1% | Sep 12, 2025 | A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials ... |
| CVE-2025-10320 | LOW | 3.1 | 0.2% | Sep 12, 2025 | A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the f... |
| CVE-2025-27238 | LOW | 3.5 | 0.2% | Sep 12, 2025 | Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user gr... |
| CVE-2025-3650 | LOW | 3.5 | 0.2% | Sep 12, 2025 | The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes o... |
| CVE-2025-10287 | LOW | 3.1 | 0.2% | Sep 12, 2025 | A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element... |
| CVE-2025-56556 | LOW | 3.8 | 0.2% | Sep 11, 2025 | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the buil... |
| CVE-2025-59047 | LOW | 2.7 | 0.4% | Sep 11, 2025 | matrix-sdk-base is the base component to build a Matrix client library. In matrix-sdk-base before 0.14.1, calling the `R... |
| CVE-2025-10255 | LOW | 3.5 | 0.3% | Sep 11, 2025 | A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the fi... |
| CVE-2025-10254 | LOW | 3.5 | 0.2% | Sep 11, 2025 | A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of ... |
| CVE-2025-10253 | LOW | 3.5 | 0.2% | Sep 11, 2025 | A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifi... |
| CVE-2025-10252 | LOW | 3.1 | 0.2% | Sep 11, 2025 | A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now