2025 CVE Vulnerabilities
45,169 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50675 | HIGH | 7.8 | 0.2% | Aug 7, 2025 | GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati... |
| CVE-2025-51629 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker... |
| CVE-2025-55138 | HIGH | 7.4 | 0.3% | Aug 7, 2025 | LinkJoin through 882f196 mishandles token ownership in password reset. |
| CVE-2025-55137 | HIGH | 7.4 | 0.3% | Aug 7, 2025 | LinkJoin through 882f196 mishandles lacks type checking in password reset. |
| CVE-2025-24000 | HIGH | 8.8 | 0.5% | Aug 7, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti... |
| CVE-2025-47907 | HIGH | 7 | 0.3% | Aug 7, 2025 | Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method ... |
| CVE-2025-35970 | HIGH | 8.7 | 0.4% | Aug 7, 2025 | On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t... |
| CVE-2025-29866 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i... |
| CVE-2025-8578 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2025-8576 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he... |
| CVE-2025-29865 | HIGH | 8.7 | 0.4% | Aug 7, 2025 | : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade... |
| CVE-2025-54882 | HIGH | 7.1 | 0.2% | Aug 7, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.... |
| CVE-2025-3770 | HIGH | 7 | 0.1% | Aug 7, 2025 | EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes... |
| CVE-2025-54788 | HIGH | 8.8 | 0.4% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an... |
| CVE-2025-54785 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.... |
| CVE-2025-7770 | HIGH | 8.7 | 0.5% | Aug 6, 2025 | Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are genera... |
| CVE-2025-7769 | HIGH | 8.7 | 16.2% | Aug 6, 2025 | Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE... |
| CVE-2025-6634 | HIGH | 7.8 | 0.2% | Aug 6, 2025 | A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili... |
| CVE-2025-6633 | HIGH | 7.8 | 0.2% | Aug 6, 2025 | A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ... |
| CVE-2025-6632 | HIGH | 7.8 | 0.2% | Aug 6, 2025 | A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerabi... |
| CVE-2025-51056 | HIGH | 8.2 | 0.5% | Aug 6, 2025 | An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t... |
| CVE-2025-51055 | HIGH | 8.6 | 0.3% | Aug 6, 2025 | Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202... |
| CVE-2025-47908 | HIGH | 7.5 | 0.5% | Aug 6, 2025 | Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A... |
| CVE-2025-51624 | HIGH | 7.6 | 0.3% | Aug 6, 2025 | Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0. |
| CVE-2025-46659 | HIGH | 7.5 | 0.3% | Aug 6, 2025 | An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now