2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54886HIGH8.4skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below...
CVE-2025-8702HIGH8.8A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0....
CVE-2025-8701HIGH8.8A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic...
CVE-2025-53787HIGH7.5Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53774HIGH7.5Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-26513HIGH7.8The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ...
CVE-2025-48709HIGH7.8BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta...
CVE-2025-47219HIGH8.1In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil...
CVE-2025-55077HIGH7.4Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s...
CVE-2025-50675HIGH7.8GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati...
CVE-2025-51629HIGH8.8A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker...
CVE-2025-55138HIGH7.4LinkJoin through 882f196 mishandles token ownership in password reset.
CVE-2025-55137HIGH7.4LinkJoin through 882f196 mishandles lacks type checking in password reset.
CVE-2025-24000HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti...
CVE-2025-47907HIGH7Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method ...
CVE-2025-35970HIGH8.7On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t...
CVE-2025-29866HIGH8.8: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i...
CVE-2025-8578HIGH8.8Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor...
CVE-2025-8576HIGH8.8Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he...
CVE-2025-29865HIGH8.7: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade...
CVE-2025-54882HIGH7.1Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1....
CVE-2025-3770HIGH7EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes...
CVE-2025-54788HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an...
CVE-2025-54785HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-7770HIGH8.7Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are genera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now