2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-43264HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious...
CVE-2025-43257HIGH8.7This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab...
CVE-2025-43219HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious...
CVE-2025-43202HIGH8.8This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 1...
CVE-2025-65114HIGH7.5Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Se...
CVE-2025-58136HIGH7.5A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from...
CVE-2025-36375HIGH8.8IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I...
CVE-2025-13916HIGH7.5IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2025-67805HIGH7.5A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat...
CVE-2025-71282HIGH8.7XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ...
CVE-2025-71278HIGH8.8XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O...
CVE-2025-13855HIGH8.8IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could...
CVE-2025-14213HIGH8.3Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack...
CVE-2025-32957HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ...
CVE-2025-12886HIGH7.2The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2025-15612HIGH8.1Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k...
CVE-2025-15617HIGH8.1Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex...
CVE-2025-15616HIGH7.2Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa...
CVE-2025-15615HIGH7.5Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i...
CVE-2025-15381HIGH7.1In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p...
CVE-2025-69986HIGH7.2A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application ...
CVE-2025-13478HIGH8.4Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to...
CVE-2025-59032HIGH7.5ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi...
CVE-2025-59028HIGH7.5When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica...
CVE-2025-12805HIGH8.1A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now