2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-46278MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to...
CVE-2025-46277LOW3.3A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe...
CVE-2025-43541MEDIUM4.3A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iP...
CVE-2025-43536MEDIUM4.3A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and...
CVE-2025-43535MEDIUM4.3The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,...
CVE-2025-43533MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-43531LOW3.1A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 1...
CVE-2025-43529HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and...
CVE-2025-43526CRITICAL9.8This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac wi...
CVE-2025-43514MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to...
CVE-2025-43501MEDIUM4.3A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and ...
CVE-2025-43475MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may ...
CVE-2025-43428CRITICAL9.8A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS...
CVE-2025-14764MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the...
CVE-2025-14763MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to t...
CVE-2025-14762MEDIUM6Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to intr...
CVE-2025-14761MEDIUM6Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to intro...
CVE-2025-67787CRITICAL9.6An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allow...
CVE-2025-67781CRITICAL9.9An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ...
CVE-2025-67074MEDIUM6.5A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-67073CRITICAL9.8A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-66646HIGH7.5RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2025-66397HIGH8.3ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload...
CVE-2025-66396HIGH7.2ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th...
CVE-2025-65233MEDIUM6.1Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now