2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31273 | HIGH | 8.8 | 1.0% | Jul 30, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, mac... |
| CVE-2025-31243 | HIGH | 7.8 | 0.2% | Jul 30, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma ... |
| CVE-2025-31229 | CRITICAL | 9.1 | 0.7% | Jul 30, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read ... |
| CVE-2025-24224 | HIGH | 7.5 | 1.1% | Jul 30, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequ... |
| CVE-2025-24188 | MEDIUM | 6.5 | 0.5% | Jul 30, 2025 | A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing mal... |
| CVE-2025-24119 | HIGH | 7.8 | 0.2% | Jul 30, 2025 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7... |
| CVE-2025-54381 | CRITICAL | 9.9 | 11.1% | Jul 29, 2025 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1... |
| CVE-2025-7849 | HIGH | 8.5 | 0.2% | Jul 29, 2025 | A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may ... |
| CVE-2025-7848 | HIGH | 8.5 | 0.2% | Jul 29, 2025 | A memory corruption vulnerability due to improper input validation in lvpict.cpp exists in NI LabVIEW that may result in... |
| CVE-2025-7361 | HIGH | 8.5 | 0.3% | Jul 29, 2025 | A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary... |
| CVE-2025-54126 | MEDIUM | 5.3 | 0.6% | Jul 29, 2025 | The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA... |
| CVE-2025-4674 | HIGH | 8.6 | 0.3% | Jul 29, 2025 | The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly d... |
| CVE-2025-40600 | CRITICAL | 9.8 | 0.8% | Jul 29, 2025 | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticate... |
| CVE-2025-5684 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stor... |
| CVE-2025-53902 | MEDIUM | 4.3 | 0.3% | Jul 29, 2025 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com... |
| CVE-2025-53541 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com... |
| CVE-2025-53102 | CRITICAL | 9.8 | 0.4% | Jul 29, 2025 | Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5... |
| CVE-2025-52899 | MEDIUM | 5.3 | 0.3% | Jul 29, 2025 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com... |
| CVE-2025-52490 | HIGH | 7.3 | 0.2% | Jul 29, 2025 | An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, ther... |
| CVE-2025-45346 | HIGH | 8.1 | 0.7% | Jul 29, 2025 | SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafte... |
| CVE-2025-51045 | MEDIUM | 6.5 | 0.2% | Jul 29, 2025 | Phpgurukul Pre-School Enrollment System 1.0 contains a SQL injection vulnerability in the /admin/password-recovery.php f... |
| CVE-2025-51044 | MEDIUM | 6.5 | 0.2% | Jul 29, 2025 | phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testi... |
| CVE-2025-36071 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vul... |
| CVE-2025-33114 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under... |
| CVE-2025-33092 | HIGH | 7.8 | 0.1% | Jul 29, 2025 | IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now