2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-50675HIGH7.8GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati...
CVE-2025-51629HIGH8.8A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker...
CVE-2025-55138HIGH7.4LinkJoin through 882f196 mishandles token ownership in password reset.
CVE-2025-55137HIGH7.4LinkJoin through 882f196 mishandles lacks type checking in password reset.
CVE-2025-24000HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti...
CVE-2025-47907HIGH7Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method ...
CVE-2025-35970HIGH8.7On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t...
CVE-2025-29866HIGH8.8: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i...
CVE-2025-8578HIGH8.8Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor...
CVE-2025-8576HIGH8.8Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he...
CVE-2025-29865HIGH8.7: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade...
CVE-2025-54882HIGH7.1Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1....
CVE-2025-3770HIGH7EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes...
CVE-2025-54788HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an...
CVE-2025-54785HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-7770HIGH8.7Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are genera...
CVE-2025-7769HIGH8.7Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE...
CVE-2025-6634HIGH7.8A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili...
CVE-2025-6633HIGH7.8A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2025-6632HIGH7.8A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-51056HIGH8.2An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t...
CVE-2025-51055HIGH8.6Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202...
CVE-2025-47908HIGH7.5Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A...
CVE-2025-51624HIGH7.6Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.
CVE-2025-46659HIGH7.5An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now