2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4088MEDIUM6.5A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitr...
CVE-2025-4087MEDIUM4.8A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null c...
CVE-2025-4086MEDIUM6.5A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension ...
CVE-2025-4084MEDIUM5.7Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user int...
CVE-2025-4082MEDIUM5.9Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vul...
CVE-2025-4064MEDIUM6.9A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects...
CVE-2025-4035MEDIUM4.3A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix...
CVE-2025-3929MEDIUM6.1An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted H...
CVE-2025-1194MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, spe...
CVE-2025-3452MEDIUM4.3The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2025-2893MEDIUM5.4The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-46343MEDIUM5.4n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) t...
CVE-2025-46338MEDIUM6.1Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulner...
CVE-2025-31203MEDIUM6.5An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO...
CVE-2025-31202MEDIUM5.5A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4...
CVE-2025-31197MEDIUM5.7The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ...
CVE-2025-30445MEDIUM6.5A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7....
CVE-2025-24271MEDIUM5.4An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS...
CVE-2025-24270MEDIUM5.7This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6...
CVE-2025-24251MEDIUM6.5The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ...
CVE-2025-24179MEDIUM5.7A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3...
CVE-2025-4038MEDIUM5.5A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affect...
CVE-2025-4037MEDIUM5.5A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function...
CVE-2025-0049MEDIUM4.3When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error...
CVE-2025-34490MEDIUM6.5GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remot...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now