2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24229 | HIGH | 7.4 | 0.7% | Mar 31, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS ... |
| CVE-2025-24228 | HIGH | 7.8 | 0.3% | Mar 31, 2025 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS So... |
| CVE-2025-24221 | HIGH | 7.5 | 0.8% | Mar 31, 2025 | This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS ... |
| CVE-2025-24213 | HIGH | 7.8 | 0.4% | Mar 31, 2025 | This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5,... |
| CVE-2025-24209 | HIGH | 7 | 0.8% | Mar 31, 2025 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iP... |
| CVE-2025-24196 | HIGH | 8.8 | 0.8% | Mar 31, 2025 | A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Son... |
| CVE-2025-24180 | HIGH | 8.1 | 0.9% | Mar 31, 2025 | The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, ma... |
| CVE-2025-24173 | HIGH | 7.8 | 0.3% | Mar 31, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.... |
| CVE-2025-24170 | HIGH | 7.8 | 0.2% | Mar 31, 2025 | A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5,... |
| CVE-2025-24095 | HIGH | 7.6 | 0.6% | Mar 31, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2... |
| CVE-2025-3018 | HIGH | 7.5 | 0.4% | Mar 31, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an u... |
| CVE-2025-31694 | HIGH | 8.1 | 0.4% | Mar 31, 2025 | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affe... |
| CVE-2025-31692 | HIGH | 7.5 | 0.7% | Mar 31, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (A... |
| CVE-2025-31690 | HIGH | 8.8 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue aff... |
| CVE-2025-31689 | HIGH | 8.1 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request F... |
| CVE-2025-31686 | HIGH | 8.1 | 0.4% | Mar 31, 2025 | Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from ... |
| CVE-2025-31678 | HIGH | 8.2 | 0.3% | Mar 31, 2025 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects A... |
| CVE-2025-31677 | HIGH | 8.8 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery... |
| CVE-2025-31676 | HIGH | 8.8 | 0.5% | Mar 31, 2025 | Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before... |
| CVE-2025-31674 | HIGH | 7.5 | 0.5% | Mar 31, 2025 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2025-3015 | HIGH | 8.8 | 0.4% | Mar 31, 2025 | A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the functi... |
| CVE-2025-31123 | HIGH | 8.7 | 0.4% | Mar 31, 2025 | Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retri... |
| CVE-2025-21893 | HIGH | 7.8 | 0.2% | Mar 31, 2025 | In the Linux kernel, the following vulnerability has been resolved: keys: Fix UAF in key_put() Once a key's reference ... |
| CVE-2025-31129 | HIGH | 8.8 | 0.6% | Mar 31, 2025 | Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes... |
| CVE-2025-31125 | HIGH | 7.5 | 62.1% | Mar 31, 2025 | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now