2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11936MEDIUM5.3Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u...
CVE-2025-11934LOW2.7Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier ...
CVE-2025-11933MEDIUM6.5Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows...
CVE-2025-11932MEDIUM4.3The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info...
CVE-2025-11931HIGH8.2Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a cal...
CVE-2025-65111MEDIUM5.3SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to ...
CVE-2025-65109HIGH8.5Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and...
CVE-2025-65108CRITICAL10md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, ...
CVE-2025-65107MEDIUM6.5Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from...
CVE-2025-65106HIGH8.3LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1...
CVE-2025-65102HIGH8.7PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the inpu...
CVE-2025-65092MEDIUM6.9ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the E...
CVE-2025-43374MEDIUM4.3An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad...
CVE-2025-31266MEDIUM4.3A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f...
CVE-2025-31248MEDIUM5.5A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m...
CVE-2025-31216LOW2.4The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke...
CVE-2025-11935HIGH7.5With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy...
CVE-2025-0504MEDIUM5.4Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with th...
CVE-2025-11087HIGH8.8The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up ...
CVE-2025-36149MEDIUM5.4IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.
CVE-2025-13524MEDIUM6.8Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linu...
CVE-2025-64767CRITICAL9.1hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, th...
CVE-2025-64169MEDIUM4.9Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to befo...
CVE-2025-62626HIGH7.2Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned ...
CVE-2025-62609HIGH7.5MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now