2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-46313MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ...
CVE-2025-46308MEDIUM5.3An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, ma...
CVE-2025-46293MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab...
CVE-2025-43339MEDIUM5.5An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious...
CVE-2025-43278MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be ab...
CVE-2025-30459MEDIUM5.5A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be ...
CVE-2025-30431MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent...
CVE-2025-24268MEDIUM5.5A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m...
CVE-2025-24165MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma ...
CVE-2025-7064MEDIUM6.6Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2...
CVE-2025-8444MEDIUM6.4The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl...
CVE-2025-62851MEDIUM4.4A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator ac...
CVE-2025-55659MEDIUM6.5A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker...
CVE-2025-55658MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media...
CVE-2025-55651MEDIUM5.5A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows...
CVE-2025-54509MEDIUM4Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg...
CVE-2025-67862MEDIUM6.7An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti...
CVE-2025-40808MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),...
CVE-2025-62858MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-71315MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk...
CVE-2025-65640MEDIUM6.3Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5....
CVE-2025-52611MEDIUM4.3HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ...
CVE-2025-52609MEDIUM5.3HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by...
CVE-2025-52608MEDIUM4.3HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s...
CVE-2025-52606MEDIUM4.3HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now