2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54886 | HIGH | 8.4 | 0.2% | Aug 8, 2025 | skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below... |
| CVE-2025-8702 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0.... |
| CVE-2025-8701 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic... |
| CVE-2025-53787 | HIGH | 7.5 | 0.6% | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-53774 | HIGH | 7.5 | 0.5% | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-26513 | HIGH | 7.8 | 0.1% | Aug 7, 2025 | The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ... |
| CVE-2025-48709 | HIGH | 7.8 | 0.1% | Aug 7, 2025 | BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta... |
| CVE-2025-47219 | HIGH | 8.1 | 0.6% | Aug 7, 2025 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil... |
| CVE-2025-55077 | HIGH | 7.4 | 0.2% | Aug 7, 2025 | Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s... |
| CVE-2025-50675 | HIGH | 7.8 | 0.2% | Aug 7, 2025 | GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati... |
| CVE-2025-51629 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker... |
| CVE-2025-55138 | HIGH | 7.4 | 0.3% | Aug 7, 2025 | LinkJoin through 882f196 mishandles token ownership in password reset. |
| CVE-2025-55137 | HIGH | 7.4 | 0.3% | Aug 7, 2025 | LinkJoin through 882f196 mishandles lacks type checking in password reset. |
| CVE-2025-24000 | HIGH | 8.8 | 0.5% | Aug 7, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti... |
| CVE-2025-47907 | HIGH | 7 | 0.3% | Aug 7, 2025 | Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method ... |
| CVE-2025-35970 | HIGH | 8.7 | 0.4% | Aug 7, 2025 | On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t... |
| CVE-2025-29866 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i... |
| CVE-2025-8578 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2025-8576 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he... |
| CVE-2025-29865 | HIGH | 8.7 | 0.4% | Aug 7, 2025 | : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade... |
| CVE-2025-54882 | HIGH | 7.1 | 0.2% | Aug 7, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.... |
| CVE-2025-3770 | HIGH | 7 | 0.1% | Aug 7, 2025 | EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes... |
| CVE-2025-54788 | HIGH | 8.8 | 0.4% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an... |
| CVE-2025-54785 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.... |
| CVE-2025-7770 | HIGH | 8.7 | 0.5% | Aug 6, 2025 | Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are genera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now