2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43264 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious... |
| CVE-2025-43257 | HIGH | 8.7 | 0.2% | Apr 2, 2026 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab... |
| CVE-2025-43219 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious... |
| CVE-2025-43202 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 1... |
| CVE-2025-65114 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Se... |
| CVE-2025-58136 | HIGH | 7.5 | 0.7% | Apr 2, 2026 | A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from... |
| CVE-2025-36375 | HIGH | 8.8 | 0.2% | Apr 1, 2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I... |
| CVE-2025-13916 | HIGH | 7.5 | 0.2% | Apr 1, 2026 | IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t... |
| CVE-2025-67805 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat... |
| CVE-2025-71282 | HIGH | 8.7 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ... |
| CVE-2025-71278 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O... |
| CVE-2025-13855 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could... |
| CVE-2025-14213 | HIGH | 8.3 | 1.0% | Mar 31, 2026 | Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack... |
| CVE-2025-32957 | HIGH | 7.2 | 0.6% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ... |
| CVE-2025-12886 | HIGH | 7.2 | 0.2% | Mar 28, 2026 | The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2025-15612 | HIGH | 8.1 | 0.2% | Mar 27, 2026 | Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k... |
| CVE-2025-15617 | HIGH | 8.1 | 0.4% | Mar 27, 2026 | Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex... |
| CVE-2025-15616 | HIGH | 7.2 | 1.6% | Mar 27, 2026 | Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa... |
| CVE-2025-15615 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i... |
| CVE-2025-15381 | HIGH | 7.1 | 0.3% | Mar 27, 2026 | In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p... |
| CVE-2025-69986 | HIGH | 7.2 | 0.5% | Mar 27, 2026 | A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application ... |
| CVE-2025-13478 | HIGH | 8.4 | 0.3% | Mar 27, 2026 | Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to... |
| CVE-2025-59032 | HIGH | 7.5 | 0.7% | Mar 27, 2026 | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi... |
| CVE-2025-59028 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica... |
| CVE-2025-12805 | HIGH | 8.1 | 0.4% | Mar 26, 2026 | A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now