2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13094 | HIGH | 8.8 | 0.5% | Dec 13, 2025 | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-13089 | HIGH | 7.5 | 0.3% | Dec 13, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par... |
| CVE-2025-13077 | HIGH | 7.5 | 0.4% | Dec 13, 2025 | The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based bl... |
| CVE-2025-13970 | HIGH | 8 | 0.3% | Dec 13, 2025 | OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. Th... |
| CVE-2025-67721 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions... |
| CVE-2025-14582 | HIGH | 7.2 | 0.3% | Dec 12, 2025 | A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the ... |
| CVE-2025-67750 | HIGH | 8.4 | 0.2% | Dec 12, 2025 | Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Sal... |
| CVE-2025-46285 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iO... |
| CVE-2025-43542 | HIGH | 7.5 | 0.8% | Dec 12, 2025 | This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 a... |
| CVE-2025-43539 | HIGH | 8.8 | 6.2% | Dec 12, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i... |
| CVE-2025-43527 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe... |
| CVE-2025-43512 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.... |
| CVE-2025-43510 | HIGH | 7.8 | 0.4% | Dec 12, 2025 | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS ... |
| CVE-2025-43506 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay ... |
| CVE-2025-43494 | HIGH | 7.5 | 0.6% | Dec 12, 2025 | A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS... |
| CVE-2025-43467 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to gain root ... |
| CVE-2025-43402 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4,... |
| CVE-2025-43320 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app ... |
| CVE-2025-8083 | HIGH | 8.6 | 0.3% | Dec 12, 2025 | The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype P... |
| CVE-2025-14572 | HIGH | 8.8 | 3.1% | Dec 12, 2025 | A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAut... |
| CVE-2025-14174 | HIGH | 8.8 | 22.3% | Dec 12, 2025 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor... |
| CVE-2025-67818 | HIGH | 7.2 | 0.7% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf... |
| CVE-2025-65530 | HIGH | 8.8 | 0.3% | Dec 12, 2025 | An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw... |
| CVE-2025-14567 | HIGH | 7.5 | 0.7% | Dec 12, 2025 | A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This... |
| CVE-2025-13733 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now