2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43210MEDIUM6.3An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18...
CVE-2025-43202HIGH8.8This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 1...
CVE-2025-65114HIGH7.5Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Se...
CVE-2025-58136HIGH7.5A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from...
CVE-2025-66487MEDIUM6.5IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em...
CVE-2025-66486MEDIUM6.1IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-66485MEDIUM5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by...
CVE-2025-66484MEDIUM5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2025-66483MEDIUM6.5IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authentic...
CVE-2025-36375HIGH8.8IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I...
CVE-2025-0711Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-36373MEDIUM6.8IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I...
CVE-2025-13916HIGH7.5IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2025-66442MEDIUM5.1In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ...
CVE-2025-67807MEDIUM4.7The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer...
CVE-2025-67806MEDIUM5.3The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer...
CVE-2025-67805HIGH7.5A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat...
CVE-2025-13535MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc...
CVE-2025-15484CRITICAL9.1The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant...
CVE-2025-71282HIGH8.7XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This ...
CVE-2025-71281CRITICAL9.8XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in...
CVE-2025-71280MEDIUM5.5XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu...
CVE-2025-71279CRITICAL9.8XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may...
CVE-2025-71278HIGH8.8XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O...
CVE-2025-13855HIGH8.8IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now