2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-43512HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15....
CVE-2025-43510HIGH7.8A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS ...
CVE-2025-43506HIGH7.5A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay ...
CVE-2025-43494HIGH7.5A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS...
CVE-2025-43467HIGH7.8This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to gain root ...
CVE-2025-43402HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4,...
CVE-2025-43320HIGH7.8The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app ...
CVE-2025-8083HIGH8.6The Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to Prototype P...
CVE-2025-14572HIGH8.8A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAut...
CVE-2025-14174HIGH8.8Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor...
CVE-2025-67818HIGH7.2An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf...
CVE-2025-65530HIGH8.8An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw...
CVE-2025-14567HIGH7.5A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This...
CVE-2025-13733HIGH7.8BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via...
CVE-2025-58770HIGH8.8APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile...
CVE-2025-54981HIGH7.5Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc...
CVE-2025-36745HIGH7.8SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac...
CVE-2025-13506HIGH8.8Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo...
CVE-2025-12835HIGH7.3The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a...
CVE-2025-58137HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ...
CVE-2025-26866HIGH8.8A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi...
CVE-2025-40829HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni...
CVE-2025-67731HIGH7.5Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr...
CVE-2025-14169HIGH7.5The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec...
CVE-2025-67726HIGH7.5Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now