2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14568MEDIUM6.3A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc709...
CVE-2025-40345——In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba ...
CVE-2025-67819MEDIUM4.9An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer...
CVE-2025-67818HIGH7.2An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf...
CVE-2025-67342MEDIUM4.6RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the ...
CVE-2025-64011MEDIUM4.3Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any a...
CVE-2025-67344MEDIUM4.6jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
CVE-2025-67341MEDIUM4.6jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to uploa...
CVE-2025-66430CRITICAL9.1Plesk 18.0 has Incorrect Access Control.
CVE-2025-65854CRITICAL9.8Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and...
CVE-2025-65530HIGH8.8An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw...
CVE-2025-53960MEDIUM5.9When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., w...
CVE-2025-14567HIGH7.5A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This...
CVE-2025-14566CRITICAL9.8A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ...
CVE-2025-14565CRITICAL9.8A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec...
CVE-2025-13733HIGH7.8BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via...
CVE-2025-12843MEDIUM5.5Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.
CVE-2025-58770HIGH8.8APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile...
CVE-2025-54981HIGH7.5Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc...
CVE-2025-54947CRITICAL9.8In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists...
CVE-2025-36755LOW2.4The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under...
CVE-2025-36746MEDIUM5.4SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay...
CVE-2025-36745HIGH7.8SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac...
CVE-2025-36744LOW2.4SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device r...
CVE-2025-36743MEDIUM6.8SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now