2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14568 | MEDIUM | 6.3 | 0.2% | Dec 12, 2025 | A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc709... |
| CVE-2025-40345 | — | — | 0.2% | Dec 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba ... |
| CVE-2025-67819 | MEDIUM | 4.9 | 0.4% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer... |
| CVE-2025-67818 | HIGH | 7.2 | 0.7% | Dec 12, 2025 | An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf... |
| CVE-2025-67342 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the ... |
| CVE-2025-64011 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core/preview endpoint. Any a... |
| CVE-2025-67344 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint. |
| CVE-2025-67341 | MEDIUM | 4.6 | 0.1% | Dec 12, 2025 | jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to uploa... |
| CVE-2025-66430 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Plesk 18.0 has Incorrect Access Control. |
| CVE-2025-65854 | CRITICAL | 9.8 | 0.5% | Dec 12, 2025 | Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and... |
| CVE-2025-65530 | HIGH | 8.8 | 0.3% | Dec 12, 2025 | An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw... |
| CVE-2025-53960 | MEDIUM | 5.9 | 0.2% | Dec 12, 2025 | When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., w... |
| CVE-2025-14567 | HIGH | 7.5 | 0.7% | Dec 12, 2025 | A weakness has been identified in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This... |
| CVE-2025-14566 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ... |
| CVE-2025-14565 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec... |
| CVE-2025-13733 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via... |
| CVE-2025-12843 | MEDIUM | 5.5 | 0.2% | Dec 12, 2025 | Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. |
| CVE-2025-58770 | HIGH | 8.8 | 0.1% | Dec 12, 2025 | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile... |
| CVE-2025-54981 | HIGH | 7.5 | 0.2% | Dec 12, 2025 | Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc... |
| CVE-2025-54947 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists... |
| CVE-2025-36755 | LOW | 2.4 | 0.1% | Dec 12, 2025 | The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under... |
| CVE-2025-36746 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay... |
| CVE-2025-36745 | HIGH | 7.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac... |
| CVE-2025-36744 | LOW | 2.4 | 0.1% | Dec 12, 2025 | SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device r... |
| CVE-2025-36743 | MEDIUM | 6.8 | 0.2% | Dec 12, 2025 | SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now