2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43360 | MEDIUM | 5.5 | 0.1% | Nov 4, 2025 | The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentio... |
| CVE-2025-43350 | LOW | 2.4 | 0.2% | Nov 4, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An atta... |
| CVE-2025-43348 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ... |
| CVE-2025-43345 | MEDIUM | 5.5 | 0.1% | Nov 4, 2025 | A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPad... |
| CVE-2025-43338 | HIGH | 7.1 | 0.2% | Nov 4, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, ... |
| CVE-2025-43336 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom... |
| CVE-2025-43335 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ma... |
| CVE-2025-43334 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1... |
| CVE-2025-43323 | HIGH | 8.1 | 0.3% | Nov 4, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26... |
| CVE-2025-43322 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO... |
| CVE-2025-43309 | LOW | 2.4 | 0.1% | Nov 4, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical... |
| CVE-2025-43288 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26... |
| CVE-2025-46556 | HIGH | 7.5 | 0.3% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently ... |
| CVE-2025-35021 | MEDIUM | 6.5 | 0.3% | Nov 4, 2025 | By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restrict... |
| CVE-2025-36172 | MEDIUM | 5.4 | 0.1% | Nov 3, 2025 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0... |
| CVE-2025-34501 | HIGH | 7 | 0.2% | Nov 3, 2025 | Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple... |
| CVE-2025-11193 | MEDIUM | 6.8 | 0.1% | Nov 3, 2025 | A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application... |
| CVE-2025-63293 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user ... |
| CVE-2025-12657 | MEDIUM | 5.5 | 0.3% | Nov 3, 2025 | The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i... |
| CVE-2025-63593 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-50735 | HIGH | 7.5 | 0.8% | Nov 3, 2025 | Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot ... |
| CVE-2025-12642 | CRITICAL | 9.1 | 0.3% | Nov 3, 2025 | lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited... |
| CVE-2025-12531 | CRITICAL | 9.1 | 0.8% | Nov 3, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) atta... |
| CVE-2025-8558 | MEDIUM | 5.4 | 0.5% | Nov 3, 2025 | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo... |
| CVE-2025-45959 | — | — | — | Nov 3, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now