2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58770 | HIGH | 8.8 | 0.1% | Dec 12, 2025 | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile... |
| CVE-2025-54981 | HIGH | 7.5 | 0.2% | Dec 12, 2025 | Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc... |
| CVE-2025-36745 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac... |
| CVE-2025-13506 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo... |
| CVE-2025-12835 | HIGH | 7.3 | 0.2% | Dec 12, 2025 | The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a... |
| CVE-2025-58137 | HIGH | 8.1 | 0.3% | Dec 12, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: ... |
| CVE-2025-26866 | HIGH | 8.8 | 0.8% | Dec 12, 2025 | A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi... |
| CVE-2025-40829 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni... |
| CVE-2025-67731 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr... |
| CVE-2025-14169 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec... |
| CVE-2025-67726 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor... |
| CVE-2025-14068 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions... |
| CVE-2025-12570 | HIGH | 7.2 | 0.2% | Dec 12, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2025-67725 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously... |
| CVE-2025-67508 | HIGH | 8.4 | 0.2% | Dec 12, 2025 | gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh... |
| CVE-2025-14044 | HIGH | 8.1 | 0.5% | Dec 12, 2025 | The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ... |
| CVE-2025-13334 | HIGH | 8.1 | 0.2% | Dec 12, 2025 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi... |
| CVE-2025-12968 | HIGH | 8.8 | 0.5% | Dec 12, 2025 | The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and... |
| CVE-2025-12824 | HIGH | 8.8 | 0.8% | Dec 12, 2025 | The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ... |
| CVE-2025-13886 | HIGH | 7.5 | 0.6% | Dec 12, 2025 | The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ... |
| CVE-2025-10451 | HIGH | 8.2 | 0.1% | Dec 12, 2025 | Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption. |
| CVE-2025-67779 | HIGH | 7.5 | 18.9% | Dec 12, 2025 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den... |
| CVE-2025-66446 | HIGH | 7.5 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow... |
| CVE-2025-34506 | HIGH | 8.8 | 0.8% | Dec 11, 2025 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator... |
| CVE-2025-66586 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now