2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43465 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2025-43464 | MEDIUM | 6.5 | 0.3% | Dec 12, 2025 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visitin... |
| CVE-2025-43463 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2025-43461 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Tahoe 26.1. An app may be ab... |
| CVE-2025-43416 | MEDIUM | 5.5 | 0.4% | Dec 12, 2025 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3... |
| CVE-2025-43406 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to a... |
| CVE-2025-43393 | MEDIUM | 5.2 | 0.1% | Dec 12, 2025 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app ... |
| CVE-2025-43388 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able t... |
| CVE-2025-43381 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.1. A malicious app ma... |
| CVE-2025-43351 | MEDIUM | 5.5 | 0.1% | Dec 12, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a... |
| CVE-2025-14580 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the... |
| CVE-2025-11266 | MEDIUM | 6.8 | 0.1% | Dec 12, 2025 | An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsin... |
| CVE-2025-67734 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to... |
| CVE-2025-14373 | MEDIUM | 4.3 | 0.3% | Dec 12, 2025 | Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to... |
| CVE-2025-14372 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially per... |
| CVE-2025-8082 | MEDIUM | 6.3 | 0.2% | Dec 12, 2025 | Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inser... |
| CVE-2025-14569 | MEDIUM | 5.3 | 0.1% | Dec 12, 2025 | A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /... |
| CVE-2025-14568 | MEDIUM | 6.3 | 0.2% | Dec 12, 2025 | A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc709... |
| CVE-2025-67819 | MEDIUM | 4.9 | 0.4% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer... |
| CVE-2025-67342 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the ... |
| CVE-2025-64011 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any a... |
| CVE-2025-67344 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint. |
| CVE-2025-67341 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to uploa... |
| CVE-2025-53960 | MEDIUM | 5.9 | 0.2% | Dec 12, 2025 | When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., w... |
| CVE-2025-12843 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now