2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65854CRITICAL9.8Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and...
CVE-2025-65530HIGH8.8An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw...
CVE-2025-53960MEDIUM5.9When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., w...
CVE-2025-14567HIGH7.5A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This...
CVE-2025-14566CRITICAL9.8A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ...
CVE-2025-14565CRITICAL9.8A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec...
CVE-2025-13733HIGH7.8BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via...
CVE-2025-12843MEDIUM5.5Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.
CVE-2025-58770HIGH8.8APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile...
CVE-2025-54981HIGH7.5Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc...
CVE-2025-54947CRITICAL9.8In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists...
CVE-2025-36755LOW2.4The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under...
CVE-2025-36746MEDIUM5.4SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay...
CVE-2025-36745HIGH7.8SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac...
CVE-2025-36744LOW2.4SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device r...
CVE-2025-36743MEDIUM6.8SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste...
CVE-2025-13506HIGH8.8Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo...
CVE-2025-14442MEDIUM5.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos...
CVE-2025-14159MEDIUM4.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2025-14065MEDIUM4.3The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che...
CVE-2025-14030MEDIUM6.4The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all...
CVE-2025-12965MEDIUM6.4The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par...
CVE-2025-12408MEDIUM5.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i...
CVE-2025-12407MEDIUM4.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2025-12841MEDIUM5.3The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now