2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31196 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPa... |
| CVE-2025-31195 | MEDIUM | 6.3 | 0.1% | May 12, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to bre... |
| CVE-2025-30440 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Vent... |
| CVE-2025-24225 | MEDIUM | 6.5 | 0.4% | May 12, 2025 | An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS... |
| CVE-2025-24222 | MEDIUM | 6.5 | 0.4% | May 12, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously... |
| CVE-2025-24220 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS ... |
| CVE-2025-24155 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, m... |
| CVE-2025-24144 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadO... |
| CVE-2025-24142 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2025-24111 | MEDIUM | 5.5 | 0.2% | May 12, 2025 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3,... |
| CVE-2025-44176 | MEDIUM | 6.5 | 6.5% | May 12, 2025 | Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function. |
| CVE-2025-44175 | MEDIUM | 5.4 | 0.2% | May 12, 2025 | Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function. |
| CVE-2025-46750 | MEDIUM | 4.4 | 0.1% | May 12, 2025 | SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and ch... |
| CVE-2025-46749 | MEDIUM | 4.3 | 0.2% | May 12, 2025 | An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ... |
| CVE-2025-46747 | MEDIUM | 5.7 | 0.3% | May 12, 2025 | An authenticated user without user-management permissions could identify other user accounts. |
| CVE-2025-46746 | MEDIUM | 5.8 | 0.2% | May 12, 2025 | An administrator could discover another account's credentials. |
| CVE-2025-46745 | MEDIUM | 6.5 | 0.3% | May 12, 2025 | An authenticated user without user-management permissions could view other users account information. |
| CVE-2025-46743 | MEDIUM | 6.3 | 0.1% | May 12, 2025 | An authenticated user's token could be used by another source after the user had logged out prior to the token expiring. |
| CVE-2025-46742 | MEDIUM | 4.3 | 0.2% | May 12, 2025 | Users who were required to change their password could still access system information before changing their password |
| CVE-2025-46741 | MEDIUM | 5.7 | 0.1% | May 12, 2025 | A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred. |
| CVE-2025-47578 | MEDIUM | 6.5 | 0.2% | May 12, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS... |
| CVE-2025-46738 | MEDIUM | 6.6 | 0.2% | May 12, 2025 | An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arb... |
| CVE-2025-46611 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted sc... |
| CVE-2025-26841 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code ... |
| CVE-2025-40627 | MEDIUM | 6.1 | 0.2% | May 12, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now