2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43351MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a...
CVE-2025-43320HIGH7.8The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app ...
CVE-2025-14611CRITICAL9.8Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of th...
CVE-2025-14580MEDIUM6.1A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the...
CVE-2025-11266MEDIUM6.8An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsin...
CVE-2025-8083HIGH8.6The Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to Prototype P...
CVE-2025-67734MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to...
CVE-2025-14578CRITICAL9.8A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown functio...
CVE-2025-14572HIGH8.8A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAut...
CVE-2025-14373MEDIUM4.3Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to...
CVE-2025-14372MEDIUM6.1Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially per...
CVE-2025-14174HIGH8.8Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor...
CVE-2025-8082MEDIUM6.3Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inser...
CVE-2025-14571CRITICAL9.8A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u...
CVE-2025-14570CRITICAL9.8A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-14569MEDIUM5.3A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /...
CVE-2025-14568MEDIUM6.3A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc709...
CVE-2025-40345In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba ...
CVE-2025-67819MEDIUM4.9An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer...
CVE-2025-67818HIGH7.2An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf...
CVE-2025-67342MEDIUM4.6RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the ...
CVE-2025-64011MEDIUM4.3Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any a...
CVE-2025-67344MEDIUM4.6jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
CVE-2025-67341MEDIUM4.6jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to uploa...
CVE-2025-66430CRITICAL9.1Plesk 18.0 has Incorrect Access Control.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now