2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43351 | MEDIUM | 5.5 | 0.1% | Dec 12, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a... |
| CVE-2025-43320 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app ... |
| CVE-2025-14611 | CRITICAL | 9.8 | 50.9% | Dec 12, 2025 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of th... |
| CVE-2025-14580 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the... |
| CVE-2025-11266 | MEDIUM | 6.8 | 0.1% | Dec 12, 2025 | An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsin... |
| CVE-2025-8083 | HIGH | 8.6 | 0.3% | Dec 12, 2025 | The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype P... |
| CVE-2025-67734 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to... |
| CVE-2025-14578 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown functio... |
| CVE-2025-14572 | HIGH | 8.8 | 3.1% | Dec 12, 2025 | A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAut... |
| CVE-2025-14373 | MEDIUM | 4.3 | 0.3% | Dec 12, 2025 | Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to... |
| CVE-2025-14372 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially per... |
| CVE-2025-14174 | HIGH | 8.8 | 22.4% | Dec 12, 2025 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor... |
| CVE-2025-8082 | MEDIUM | 6.3 | 0.2% | Dec 12, 2025 | Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inser... |
| CVE-2025-14571 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u... |
| CVE-2025-14570 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-14569 | MEDIUM | 5.3 | 0.1% | Dec 12, 2025 | A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /... |
| CVE-2025-14568 | MEDIUM | 6.3 | 0.2% | Dec 12, 2025 | A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc709... |
| CVE-2025-40345 | — | — | 0.2% | Dec 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba ... |
| CVE-2025-67819 | MEDIUM | 4.9 | 0.4% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer... |
| CVE-2025-67818 | HIGH | 7.2 | 0.7% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf... |
| CVE-2025-67342 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the ... |
| CVE-2025-64011 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any a... |
| CVE-2025-67344 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint. |
| CVE-2025-67341 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to uploa... |
| CVE-2025-66430 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Plesk 18.0 has Incorrect Access Control. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now