2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58770HIGH8.8APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile...
CVE-2025-54981HIGH7.5Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc...
CVE-2025-36745HIGH7.8SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac...
CVE-2025-13506HIGH8.8Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo...
CVE-2025-12835HIGH7.3The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a...
CVE-2025-58137HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ...
CVE-2025-26866HIGH8.8A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi...
CVE-2025-40829HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni...
CVE-2025-67731HIGH7.5Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr...
CVE-2025-14169HIGH7.5The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec...
CVE-2025-67726HIGH7.5Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor...
CVE-2025-14068HIGH7.5The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions...
CVE-2025-12570HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2025-67725HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously...
CVE-2025-67508HIGH8.4gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh...
CVE-2025-14044HIGH8.1The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ...
CVE-2025-13334HIGH8.1The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi...
CVE-2025-12968HIGH8.8The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and...
CVE-2025-12824HIGH8.8The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ...
CVE-2025-13886HIGH7.5The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ...
CVE-2025-10451HIGH8.2Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
CVE-2025-67779HIGH7.5It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den...
CVE-2025-66446HIGH7.5MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow...
CVE-2025-34506HIGH8.8WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator...
CVE-2025-66586HIGH7.8In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now