2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31196MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPa...
CVE-2025-31195MEDIUM6.3The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to bre...
CVE-2025-30440MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Vent...
CVE-2025-24225MEDIUM6.5An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS...
CVE-2025-24222MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously...
CVE-2025-24220MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS ...
CVE-2025-24155MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, m...
CVE-2025-24144MEDIUM5.5An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadO...
CVE-2025-24142MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2025-24111MEDIUM5.5A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3,...
CVE-2025-44176MEDIUM6.5Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.
CVE-2025-44175MEDIUM5.4Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.
CVE-2025-46750MEDIUM4.4SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and ch...
CVE-2025-46749MEDIUM4.3An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequ...
CVE-2025-46747MEDIUM5.7An authenticated user without user-management permissions could identify other user accounts.
CVE-2025-46746MEDIUM5.8An administrator could discover another account's credentials.
CVE-2025-46745MEDIUM6.5An authenticated user without user-management permissions could view other users account information.
CVE-2025-46743MEDIUM6.3An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.
CVE-2025-46742MEDIUM4.3Users who were required to change their password could still access system information before changing their password
CVE-2025-46741MEDIUM5.7A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.
CVE-2025-47578MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS...
CVE-2025-46738MEDIUM6.6An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arb...
CVE-2025-46611MEDIUM6.1Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted sc...
CVE-2025-26841MEDIUM6.1Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code ...
CVE-2025-40627MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now