2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46278 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to... |
| CVE-2025-46277 | LOW | 3.3 | 0.2% | Dec 17, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe... |
| CVE-2025-43541 | MEDIUM | 4.3 | 32.0% | Dec 17, 2025 | A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iP... |
| CVE-2025-43536 | MEDIUM | 4.3 | 0.5% | Dec 17, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and... |
| CVE-2025-43535 | MEDIUM | 4.3 | 0.8% | Dec 17, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,... |
| CVE-2025-43533 | MEDIUM | 5.7 | 0.3% | Dec 17, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i... |
| CVE-2025-43531 | LOW | 3.1 | 0.4% | Dec 17, 2025 | A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 1... |
| CVE-2025-43529 | HIGH | 8.8 | 8.4% | Dec 17, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and... |
| CVE-2025-43526 | CRITICAL | 9.8 | 0.5% | Dec 17, 2025 | This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac wi... |
| CVE-2025-43514 | MEDIUM | 5.5 | 0.2% | Dec 17, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to... |
| CVE-2025-43501 | MEDIUM | 4.3 | 0.7% | Dec 17, 2025 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and ... |
| CVE-2025-43475 | MEDIUM | 5.5 | 0.1% | Dec 17, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may ... |
| CVE-2025-43428 | CRITICAL | 9.8 | 0.7% | Dec 17, 2025 | A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS... |
| CVE-2025-14764 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the... |
| CVE-2025-14763 | MEDIUM | 6 | 0.1% | Dec 17, 2025 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to t... |
| CVE-2025-14762 | MEDIUM | 6 | 0.2% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to intr... |
| CVE-2025-14761 | MEDIUM | 6 | 0.2% | Dec 17, 2025 | Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to intro... |
| CVE-2025-67787 | CRITICAL | 9.6 | 0.2% | Dec 17, 2025 | An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allow... |
| CVE-2025-67781 | CRITICAL | 9.9 | 0.2% | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ... |
| CVE-2025-67074 | MEDIUM | 6.5 | 0.3% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-67073 | CRITICAL | 9.8 | 0.6% | Dec 17, 2025 | A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot... |
| CVE-2025-66646 | HIGH | 7.5 | 0.6% | Dec 17, 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2025-66397 | HIGH | 8.3 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload... |
| CVE-2025-66396 | HIGH | 7.2 | 0.3% | Dec 17, 2025 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th... |
| CVE-2025-65233 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now