2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43360MEDIUM5.5The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentio...
CVE-2025-43350LOW2.4A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An atta...
CVE-2025-43348MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ...
CVE-2025-43345MEDIUM5.5A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPad...
CVE-2025-43338HIGH7.1An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, ...
CVE-2025-43336MEDIUM4.4A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom...
CVE-2025-43335MEDIUM5.5The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ma...
CVE-2025-43334MEDIUM5.5This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1...
CVE-2025-43323HIGH8.1This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26...
CVE-2025-43322MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO...
CVE-2025-43309LOW2.4A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical...
CVE-2025-43288MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26...
CVE-2025-46556HIGH7.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently ...
CVE-2025-35021MEDIUM6.5By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restrict...
CVE-2025-36172MEDIUM5.4IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0...
CVE-2025-34501HIGH7Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple...
CVE-2025-11193MEDIUM6.8A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application...
CVE-2025-63293MEDIUM6.5FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user ...
CVE-2025-12657MEDIUM5.5The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i...
CVE-2025-63593MEDIUM6.1Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-50735HIGH7.5Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot ...
CVE-2025-12642CRITICAL9.1lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited...
CVE-2025-12531CRITICAL9.1IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) atta...
CVE-2025-8558MEDIUM5.4Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo...
CVE-2025-45959Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now