2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-24164MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS ...
CVE-2025-24157MEDIUM5.6A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS So...
CVE-2025-24148MEDIUM5.5This issue was addressed with improved handling of executable types. This issue is fixed in macOS Sequoia 15.4, macOS So...
CVE-2025-24097MEDIUM5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS ...
CVE-2025-3057MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core...
CVE-2025-3036MEDIUM6.1A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b...
CVE-2025-3017MEDIUM5.3A vulnerability, which was classified as critical, has been found in TA-Lib up to 0.6.4. This issue affects the function...
CVE-2025-31697MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter S...
CVE-2025-31696MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS...
CVE-2025-31695MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field ...
CVE-2025-31693MEDIUM6.6Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (A...
CVE-2025-31688MEDIUM6.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This iss...
CVE-2025-31687MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SpamSpan fi...
CVE-2025-31684MEDIUM6.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue aff...
CVE-2025-31683MEDIUM6.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affect...
CVE-2025-31682MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag ...
CVE-2025-31680MEDIUM6.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue ...
CVE-2025-31679MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Er...
CVE-2025-31675MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core...
CVE-2025-31673MEDIUM4.6Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro...
CVE-2025-3016MEDIUM6.5A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affect...
CVE-2025-3010MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this i...
CVE-2025-3009MEDIUM6.3A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown f...
CVE-2025-31124MEDIUM5.3Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un...
CVE-2025-3008MEDIUM5.5A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/pop...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now