2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24164 | MEDIUM | 5.5 | 0.3% | Mar 31, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS ... |
| CVE-2025-24157 | MEDIUM | 5.6 | 0.6% | Mar 31, 2025 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS So... |
| CVE-2025-24148 | MEDIUM | 5.5 | 0.2% | Mar 31, 2025 | This issue was addressed with improved handling of executable types. This issue is fixed in macOS Sequoia 15.4, macOS So... |
| CVE-2025-24097 | MEDIUM | 5 | 0.3% | Mar 31, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS ... |
| CVE-2025-3057 | MEDIUM | 6.1 | 0.3% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core... |
| CVE-2025-3036 | MEDIUM | 6.1 | 0.3% | Mar 31, 2025 | A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b... |
| CVE-2025-3017 | MEDIUM | 5.3 | 0.2% | Mar 31, 2025 | A vulnerability, which was classified as critical, has been found in TA-Lib up to 0.6.4. This issue affects the function... |
| CVE-2025-31697 | MEDIUM | 6.1 | 0.2% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter S... |
| CVE-2025-31696 | MEDIUM | 6.1 | 0.2% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS... |
| CVE-2025-31695 | MEDIUM | 6.1 | 0.2% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field ... |
| CVE-2025-31693 | MEDIUM | 6.6 | 0.7% | Mar 31, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (A... |
| CVE-2025-31688 | MEDIUM | 6.8 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This iss... |
| CVE-2025-31687 | MEDIUM | 6.1 | 0.2% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SpamSpan fi... |
| CVE-2025-31684 | MEDIUM | 6.8 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue aff... |
| CVE-2025-31683 | MEDIUM | 6.8 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affect... |
| CVE-2025-31682 | MEDIUM | 4.8 | 0.2% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag ... |
| CVE-2025-31680 | MEDIUM | 6.8 | 0.2% | Mar 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue ... |
| CVE-2025-31679 | MEDIUM | 6.1 | 0.2% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Er... |
| CVE-2025-31675 | MEDIUM | 5.4 | 0.4% | Mar 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core... |
| CVE-2025-31673 | MEDIUM | 4.6 | 0.3% | Mar 31, 2025 | Incorrect Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: fro... |
| CVE-2025-3016 | MEDIUM | 6.5 | 0.5% | Mar 31, 2025 | A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affect... |
| CVE-2025-3010 | MEDIUM | 4.8 | 0.2% | Mar 31, 2025 | A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this i... |
| CVE-2025-3009 | MEDIUM | 6.3 | 0.3% | Mar 31, 2025 | A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown f... |
| CVE-2025-31124 | MEDIUM | 5.3 | 0.5% | Mar 31, 2025 | Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un... |
| CVE-2025-3008 | MEDIUM | 5.5 | 1.1% | Mar 31, 2025 | A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/pop... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now