2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-43257HIGH8.7This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab...
CVE-2025-43219HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious...
CVE-2025-43202HIGH8.8This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 1...
CVE-2025-65114HIGH7.5Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Se...
CVE-2025-58136HIGH7.5A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from...
CVE-2025-36375HIGH8.8IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I...
CVE-2025-13916HIGH7.5IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2025-67805HIGH7.5A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat...
CVE-2025-71282HIGH8.7XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ...
CVE-2025-71278HIGH8.8XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O...
CVE-2025-13855HIGH8.8IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could...
CVE-2025-14213HIGH8.3Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack...
CVE-2025-32957HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to ...
CVE-2025-12886HIGH7.2The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2025-15612HIGH8.1Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k...
CVE-2025-15617HIGH8.1Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex...
CVE-2025-15616HIGH7.2Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search pa...
CVE-2025-15615HIGH7.5Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i...
CVE-2025-15381HIGH7.1In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p...
CVE-2025-69986HIGH7.2A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application ...
CVE-2025-13478HIGH8.4Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to...
CVE-2025-59032HIGH7.5ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi...
CVE-2025-59028HIGH7.5When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica...
CVE-2025-12805HIGH8.1A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to ...
CVE-2025-55263HIGH7.5HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now