2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-31273HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, mac...
CVE-2025-31243HIGH7.8A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma ...
CVE-2025-31229CRITICAL9.1A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read ...
CVE-2025-24224HIGH7.5The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequ...
CVE-2025-24188MEDIUM6.5A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing mal...
CVE-2025-24119HIGH7.8This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7...
CVE-2025-54381CRITICAL9.9BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1...
CVE-2025-7849HIGH8.5A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may ...
CVE-2025-7848HIGH8.5A memory corruption vulnerability due to improper input validation in lvpict.cpp exists in NI LabVIEW that may result in...
CVE-2025-7361HIGH8.5A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary...
CVE-2025-54126MEDIUM5.3The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA...
CVE-2025-4674HIGH8.6The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly d...
CVE-2025-40600CRITICAL9.8Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticate...
CVE-2025-5684MEDIUM6.4The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stor...
CVE-2025-53902MEDIUM4.3Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com...
CVE-2025-53541MEDIUM5.4Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com...
CVE-2025-53102CRITICAL9.8Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5...
CVE-2025-52899MEDIUM5.3Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com...
CVE-2025-52490HIGH7.3An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, ther...
CVE-2025-45346HIGH8.1SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafte...
CVE-2025-51045MEDIUM6.5Phpgurukul Pre-School Enrollment System 1.0 contains a SQL injection vulnerability in the /admin/password-recovery.php f...
CVE-2025-51044MEDIUM6.5phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testi...
CVE-2025-36071HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vul...
CVE-2025-33114HIGH7.5IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under...
CVE-2025-33092HIGH7.8IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now