2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43512 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.... |
| CVE-2025-43510 | HIGH | 7.8 | 0.3% | Dec 12, 2025 | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS ... |
| CVE-2025-43506 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay ... |
| CVE-2025-43494 | HIGH | 7.5 | 0.5% | Dec 12, 2025 | A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS... |
| CVE-2025-43467 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to gain root ... |
| CVE-2025-43402 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4,... |
| CVE-2025-43320 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app ... |
| CVE-2025-8083 | HIGH | 8.6 | 0.3% | Dec 12, 2025 | The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype P... |
| CVE-2025-14572 | HIGH | 8.8 | 3.1% | Dec 12, 2025 | A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAut... |
| CVE-2025-14174 | HIGH | 8.8 | 22.4% | Dec 12, 2025 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor... |
| CVE-2025-67818 | HIGH | 7.2 | 0.7% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf... |
| CVE-2025-65530 | HIGH | 8.8 | 0.3% | Dec 12, 2025 | An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw... |
| CVE-2025-14567 | HIGH | 7.5 | 0.7% | Dec 12, 2025 | A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This... |
| CVE-2025-13733 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via... |
| CVE-2025-58770 | HIGH | 8.8 | 0.1% | Dec 12, 2025 | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile... |
| CVE-2025-54981 | HIGH | 7.5 | 0.2% | Dec 12, 2025 | Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc... |
| CVE-2025-36745 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac... |
| CVE-2025-13506 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo... |
| CVE-2025-12835 | HIGH | 7.3 | 0.2% | Dec 12, 2025 | The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a... |
| CVE-2025-58137 | HIGH | 8.1 | 0.3% | Dec 12, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ... |
| CVE-2025-26866 | HIGH | 8.8 | 0.8% | Dec 12, 2025 | A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi... |
| CVE-2025-40829 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni... |
| CVE-2025-67731 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr... |
| CVE-2025-14169 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec... |
| CVE-2025-67726 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now