2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43335MEDIUM5.5The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ma...
CVE-2025-43334MEDIUM5.5This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1...
CVE-2025-43322MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO...
CVE-2025-43288MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26...
CVE-2025-35021MEDIUM6.5By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restrict...
CVE-2025-36172MEDIUM5.4IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0...
CVE-2025-11193MEDIUM6.8A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application...
CVE-2025-63293MEDIUM6.5FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user ...
CVE-2025-12657MEDIUM5.5The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i...
CVE-2025-63593MEDIUM6.1Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-8558MEDIUM5.4Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo...
CVE-2025-50363MEDIUM5.4Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name...
CVE-2025-10280MEDIUM6.1IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels includin...
CVE-2025-63450MEDIUM5.4Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
CVE-2025-63449MEDIUM5.4Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
CVE-2025-63448MEDIUM6.1Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
CVE-2025-63447MEDIUM6.1Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
CVE-2025-63446MEDIUM6.1Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.
CVE-2025-36092MEDIUM6.5IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of ...
CVE-2025-36091MEDIUM4.3IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards t...
CVE-2025-63443MEDIUM5.4School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.
CVE-2025-63442MEDIUM4.6Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. T...
CVE-2025-60892MEDIUM6.8An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-...
CVE-2025-45663MEDIUM6.5An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
CVE-2025-29699MEDIUM6.5NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now