2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67870 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67869 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67868 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67867 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67866 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67865 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67864 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-67863 | — | — | — | Dec 13, 2025 | Rejected reason: Not used |
| CVE-2025-36754 | CRITICAL | 9.3 | 0.1% | Dec 13, 2025 | The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication check... |
| CVE-2025-36753 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to ... |
| CVE-2025-36752 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows si... |
| CVE-2025-36751 | CRITICAL | 9.4 | 0.1% | Dec 13, 2025 | Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker wi... |
| CVE-2025-36750 | MEDIUM | 5.4 | 0.1% | Dec 13, 2025 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be di... |
| CVE-2025-36748 | MEDIUM | 5.4 | 0.1% | Dec 13, 2025 | ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScr... |
| CVE-2025-36747 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish ... |
| CVE-2025-14620 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno... |
| CVE-2025-14619 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-14617 | MEDIUM | 5.3 | 0.1% | Dec 13, 2025 | A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown func... |
| CVE-2025-14607 | MEDIUM | 6.3 | 0.2% | Dec 13, 2025 | A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicom... |
| CVE-2025-14606 | MEDIUM | 5 | 0.2% | Dec 13, 2025 | A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the funct... |
| CVE-2025-14590 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown functio... |
| CVE-2025-14589 | HIGH | 8.8 | 0.3% | Dec 13, 2025 | A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing... |
| CVE-2025-14588 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown co... |
| CVE-2025-14587 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of th... |
| CVE-2025-14586 | CRITICAL | 9.8 | 2.5% | Dec 13, 2025 | A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprint... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now