2025 CVE Vulnerabilities
45,160 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10290 | MEDIUM | 6.5 | 0.2% | Sep 16, 2025 | Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the ... |
| CVE-2025-8446 | MEDIUM | 4.3 | 0.2% | Sep 16, 2025 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab... |
| CVE-2025-6575 | MEDIUM | 6.1 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dolusoft Om... |
| CVE-2025-56697 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks ... |
| CVE-2025-26711 | MEDIUM | 5.7 | 0.2% | Sep 16, 2025 | There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa... |
| CVE-2025-10015 | MEDIUM | 4.8 | 0.1% | Sep 16, 2025 | The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its ... |
| CVE-2025-2404 | MEDIUM | 4.3 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Inform... |
| CVE-2025-5519 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in ArgusTech BILGER allows Choosing Message Identifier. ... |
| CVE-2025-5518 | MEDIUM | 6.5 | 0.4% | Sep 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech BILGER allows Exploitat... |
| CVE-2025-9808 | MEDIUM | 5.3 | 0.8% | Sep 16, 2025 | The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,... |
| CVE-2025-43375 | MEDIUM | 5.5 | 0.3% | Sep 15, 2025 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may... |
| CVE-2025-43370 | MEDIUM | 4 | 0.3% | Sep 15, 2025 | A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly larg... |
| CVE-2025-43369 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26. An app may be able t... |
| CVE-2025-43368 | MEDIUM | 4.3 | 0.7% | Sep 15, 2025 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadO... |
| CVE-2025-43367 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app... |
| CVE-2025-43366 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be ... |
| CVE-2025-43356 | MEDIUM | 6.5 | 0.6% | Sep 15, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iO... |
| CVE-2025-43355 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS... |
| CVE-2025-43354 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26,... |
| CVE-2025-43353 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS... |
| CVE-2025-43346 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18... |
| CVE-2025-43337 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS T... |
| CVE-2025-43332 | MEDIUM | 5.2 | 0.2% | Sep 15, 2025 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 1... |
| CVE-2025-43331 | MEDIUM | 4 | 0.2% | Sep 15, 2025 | A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Tahoe 26. An app... |
| CVE-2025-43327 | MEDIUM | 6.5 | 0.4% | Sep 15, 2025 | The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26. Visiting a malicio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now