2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10738 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ paramet... |
| CVE-2025-14585 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functi... |
| CVE-2025-14584 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /a... |
| CVE-2025-14583 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /a... |
| CVE-2025-14611 | CRITICAL | 9.8 | 50.9% | Dec 12, 2025 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of th... |
| CVE-2025-14578 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown functio... |
| CVE-2025-14571 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u... |
| CVE-2025-14570 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-66430 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Plesk 18.0 has Incorrect Access Control. |
| CVE-2025-65854 | CRITICAL | 9.8 | 0.5% | Dec 12, 2025 | Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and... |
| CVE-2025-14566 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ... |
| CVE-2025-14565 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec... |
| CVE-2025-54947 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists... |
| CVE-2025-58130 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11... |
| CVE-2025-67728 | CRITICAL | 9.8 | 0.6% | Dec 12, 2025 | Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau... |
| CVE-2025-67727 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t... |
| CVE-2025-14344 | CRITICAL | 9.8 | 0.5% | Dec 12, 2025 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f... |
| CVE-2025-12963 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable ... |
| CVE-2025-66419 | CRITICAL | 10 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to ... |
| CVE-2025-64721 | CRITICAL | 10 | 0.6% | Dec 11, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.... |
| CVE-2025-66590 | CRITICAL | 9.8 | 0.3% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker t... |
| CVE-2025-66589 | CRITICAL | 9.1 | 0.3% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to... |
| CVE-2025-66588 | CRITICAL | 9.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by a... |
| CVE-2025-14537 | CRITICAL | 9.8 | 0.4% | Dec 11, 2025 | A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some ... |
| CVE-2025-36937 | CRITICAL | 9.8 | 0.2% | Dec 11, 2025 | In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now