2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48065MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-48055MEDIUM5.4Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse ...
CVE-2025-63384MEDIUM6.5A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exce...
CVE-2025-60876MEDIUM6.5BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/que...
CVE-2025-56503MEDIUM6.5An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate ...
CVE-2025-47932MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-33150MEDIUM5.3IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hid...
CVE-2025-12729MEDIUM4.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker wh...
CVE-2025-12728MEDIUM4.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker wh...
CVE-2025-12447MEDIUM4.2Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convin...
CVE-2025-12446MEDIUM4.2Incorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a use...
CVE-2025-12445MEDIUM6.5Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install ...
CVE-2025-12444MEDIUM4.2Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a...
CVE-2025-12443MEDIUM4.3Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bound...
CVE-2025-12441MEDIUM4.3Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds m...
CVE-2025-12440MEDIUM5.3Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced...
CVE-2025-12439MEDIUM5.5Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local ...
CVE-2025-12436MEDIUM5.9Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install ...
CVE-2025-12435MEDIUM5.4Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform...
CVE-2025-12434MEDIUM4.2Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng...
CVE-2025-12433MEDIUM4.3Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of b...
CVE-2025-12431MEDIUM6.5Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a u...
CVE-2025-47773MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-43079MEDIUM6.3The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported ve...
CVE-2025-63834MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now