2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24137 | HIGH | 8 | 0.9% | Jan 27, 2025 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.... |
| CVE-2025-24135 | HIGH | 7.8 | 0.2% | Jan 27, 2025 | This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able... |
| CVE-2025-24129 | HIGH | 7.5 | 1.3% | Jan 27, 2025 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoi... |
| CVE-2025-24126 | HIGH | 7.3 | 1.3% | Jan 27, 2025 | An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sono... |
| CVE-2025-24120 | HIGH | 7.5 | 0.9% | Jan 27, 2025 | This issue was addressed by improved management of object lifetimes. This issue is fixed in macOS Sequoia 15.3, macOS So... |
| CVE-2025-24118 | HIGH | 7.1 | 3.6% | Jan 27, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS S... |
| CVE-2025-24107 | HIGH | 7.8 | 0.2% | Jan 27, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS S... |
| CVE-2025-0734 | HIGH | 7.2 | 0.5% | Jan 27, 2025 | A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the... |
| CVE-2025-24368 | HIGH | 7.5 | 0.5% | Jan 27, 2025 | Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php... |
| CVE-2025-24367 | HIGH | 8.8 | 51.5% | Jan 27, 2025 | Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation... |
| CVE-2025-24365 | HIGH | 7.5 | 0.7% | Jan 27, 2025 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can o... |
| CVE-2025-24364 | HIGH | 7.2 | 1.0% | Jan 27, 2025 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with ... |
| CVE-2025-24357 | HIGH | 8.8 | 0.7% | Jan 27, 2025 | vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterato... |
| CVE-2025-24356 | HIGH | 7.5 | 0.7% | Jan 27, 2025 | fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknow... |
| CVE-2025-22604 | HIGH | 7.2 | 5.3% | Jan 27, 2025 | Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, auth... |
| CVE-2025-24783 | HIGH | 7.5 | 0.8% | Jan 27, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apach... |
| CVE-2025-24782 | HIGH | 8.8 | 0.5% | Jan 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-24742 | HIGH | 8.8 | 0.2% | Jan 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from... |
| CVE-2025-24734 | HIGH | 8.8 | 0.5% | Jan 27, 2025 | Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege... |
| CVE-2025-24708 | HIGH | 7.1 | 0.2% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynam... |
| CVE-2025-24626 | HIGH | 7.1 | 0.2% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Music S... |
| CVE-2025-23982 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | Missing Authorization vulnerability in Gopi krishnan Fare Calculator fare-calculator allows Stored XSS.This issue affect... |
| CVE-2025-23756 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivanchernyakov Law... |
| CVE-2025-23754 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ulrich Sossou The ... |
| CVE-2025-23752 | HIGH | 7.1 | 0.3% | Jan 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clifton Griffin CG... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now