2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62780MEDIUM5.4changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha...
CVE-2025-49145MEDIUM6.5Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri...
CVE-2025-63617MEDIUM6.5ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulne...
CVE-2025-63296MEDIUM6.5KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot...
CVE-2025-48878MEDIUM4.3Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct...
CVE-2025-48065MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-48055MEDIUM5.4Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse ...
CVE-2025-63384MEDIUM6.5A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exce...
CVE-2025-60876MEDIUM6.5BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/que...
CVE-2025-56503MEDIUM6.5An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate ...
CVE-2025-47932MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ...
CVE-2025-33150MEDIUM5.3IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hid...
CVE-2025-12729MEDIUM4.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker wh...
CVE-2025-12728MEDIUM4.2Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker wh...
CVE-2025-12447MEDIUM4.2Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convin...
CVE-2025-12446MEDIUM4.2Incorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a use...
CVE-2025-12445MEDIUM6.5Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install ...
CVE-2025-12444MEDIUM4.2Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a...
CVE-2025-12443MEDIUM4.3Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bound...
CVE-2025-12441MEDIUM4.3Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds m...
CVE-2025-12440MEDIUM5.3Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced...
CVE-2025-12439MEDIUM5.5Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local ...
CVE-2025-12436MEDIUM5.9Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install ...
CVE-2025-12435MEDIUM5.4Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform...
CVE-2025-12434MEDIUM4.2Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now