2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65854 | CRITICAL | 9.8 | 0.5% | Dec 12, 2025 | Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and... |
| CVE-2025-65530 | HIGH | 8.8 | 0.3% | Dec 12, 2025 | An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw... |
| CVE-2025-53960 | MEDIUM | 5.9 | 0.2% | Dec 12, 2025 | When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., w... |
| CVE-2025-14567 | HIGH | 7.5 | 0.7% | Dec 12, 2025 | A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This... |
| CVE-2025-14566 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ... |
| CVE-2025-14565 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec... |
| CVE-2025-13733 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via... |
| CVE-2025-12843 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. |
| CVE-2025-58770 | HIGH | 8.8 | 0.1% | Dec 12, 2025 | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile... |
| CVE-2025-54981 | HIGH | 7.5 | 0.2% | Dec 12, 2025 | Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc... |
| CVE-2025-54947 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists... |
| CVE-2025-36755 | LOW | 2.4 | 0.1% | Dec 12, 2025 | The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under... |
| CVE-2025-36746 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay... |
| CVE-2025-36745 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac... |
| CVE-2025-36744 | LOW | 2.4 | 0.1% | Dec 12, 2025 | SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device r... |
| CVE-2025-36743 | MEDIUM | 6.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste... |
| CVE-2025-13506 | HIGH | 8.8 | 0.4% | Dec 12, 2025 | Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo... |
| CVE-2025-14442 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos... |
| CVE-2025-14159 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2025-14065 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che... |
| CVE-2025-14030 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all... |
| CVE-2025-12965 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par... |
| CVE-2025-12408 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2025-12407 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2025-12841 | MEDIUM | 5.3 | 0.7% | Dec 12, 2025 | The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now