2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46313 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ... |
| CVE-2025-46308 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, ma... |
| CVE-2025-46293 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab... |
| CVE-2025-43339 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious... |
| CVE-2025-43278 | MEDIUM | 5.5 | 0.2% | Jun 11, 2026 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab... |
| CVE-2025-30459 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be ... |
| CVE-2025-30431 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent... |
| CVE-2025-24268 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2025-24165 | MEDIUM | 5.5 | 0.1% | Jun 11, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma ... |
| CVE-2025-7064 | MEDIUM | 6.6 | 0.1% | Jun 11, 2026 | Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2... |
| CVE-2025-8444 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl... |
| CVE-2025-62851 | MEDIUM | 4.4 | 0.3% | Jun 10, 2026 | A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator ac... |
| CVE-2025-55659 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker... |
| CVE-2025-55658 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media... |
| CVE-2025-55651 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows... |
| CVE-2025-54509 | MEDIUM | 4 | 0.1% | Jun 9, 2026 | Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg... |
| CVE-2025-67862 | MEDIUM | 6.7 | 0.1% | Jun 9, 2026 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti... |
| CVE-2025-40808 | MEDIUM | 6.9 | 0.2% | Jun 9, 2026 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),... |
| CVE-2025-62858 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker... |
| CVE-2025-71315 | MEDIUM | 5.5 | 0.1% | Jun 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk... |
| CVE-2025-65640 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.... |
| CVE-2025-52611 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ... |
| CVE-2025-52609 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by... |
| CVE-2025-52608 | MEDIUM | 4.3 | 0.1% | Jun 4, 2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s... |
| CVE-2025-52606 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now