2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24229HIGH7.4A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS ...
CVE-2025-24228HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS So...
CVE-2025-24221HIGH7.5This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS ...
CVE-2025-24213HIGH7.8This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5,...
CVE-2025-24209HIGH7A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iP...
CVE-2025-24196HIGH8.8A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Son...
CVE-2025-24180HIGH8.1The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, ma...
CVE-2025-24173HIGH7.8This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17....
CVE-2025-24170HIGH7.8A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5,...
CVE-2025-24095HIGH7.6This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2...
CVE-2025-3018HIGH7.5A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an u...
CVE-2025-31694HIGH8.1Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affe...
CVE-2025-31692HIGH7.5Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (A...
CVE-2025-31690HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue aff...
CVE-2025-31689HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request F...
CVE-2025-31686HIGH8.1Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from ...
CVE-2025-31678HIGH8.2Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects A...
CVE-2025-31677HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery...
CVE-2025-31676HIGH8.8Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before...
CVE-2025-31674HIGH7.5Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2025-3015HIGH8.8A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the functi...
CVE-2025-31123HIGH8.7Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retri...
CVE-2025-21893HIGH7.8In the Linux kernel, the following vulnerability has been resolved: keys: Fix UAF in key_put() Once a key's reference ...
CVE-2025-31129HIGH8.8Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes...
CVE-2025-31125HIGH7.5Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now