2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43231 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access... |
| CVE-2025-43208 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl... |
| CVE-2025-43207 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | This issue was addressed with improved entitlements. This issue is fixed in macOS Tahoe 26. An app may be able to access... |
| CVE-2025-43204 | HIGH | 7.8 | 0.3% | Sep 15, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to b... |
| CVE-2025-43203 | MEDIUM | 4 | 0.2% | Sep 15, 2025 | The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iP... |
| CVE-2025-43190 | MEDIUM | 5.5 | 0.3% | Sep 15, 2025 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i... |
| CVE-2025-31271 | HIGH | 7.5 | 0.4% | Sep 15, 2025 | This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime cal... |
| CVE-2025-31270 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl... |
| CVE-2025-31269 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26... |
| CVE-2025-31268 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma ... |
| CVE-2025-31255 | CRITICAL | 9.8 | 1.5% | Sep 15, 2025 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS ... |
| CVE-2025-31254 | MEDIUM | 5.4 | 0.5% | Sep 15, 2025 | This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processin... |
| CVE-2025-30468 | MEDIUM | 6.5 | 0.3% | Sep 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsin... |
| CVE-2025-24197 | MEDIUM | 5.5 | 0.2% | Sep 15, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta... |
| CVE-2025-24133 | — | — | — | Sep 15, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-24088 | HIGH | 7.5 | 0.4% | Sep 15, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to overrid... |
| CVE-2025-10485 | MEDIUM | 4.3 | 0.4% | Sep 15, 2025 | A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue i... |
| CVE-2025-10483 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an ... |
| CVE-2025-6999 | MEDIUM | 6.9 | 0.5% | Sep 15, 2025 | An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote... |
| CVE-2025-6947 | MEDIUM | 4.8 | 0.3% | Sep 15, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi... |
| CVE-2025-57118 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php |
| CVE-2025-57117 | MEDIUM | 5.4 | 0.4% | Sep 15, 2025 | A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execut... |
| CVE-2025-56274 | HIGH | 8.1 | 0.4% | Sep 15, 2025 | SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows ... |
| CVE-2025-43802 | MEDIUM | 6.1 | 0.2% | Sep 15, 2025 | Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7... |
| CVE-2025-43797 | MEDIUM | 5.4 | 0.2% | Sep 15, 2025 | In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now