2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54392MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d...
CVE-2025-7054MEDIUM6.5Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_...
CVE-2025-55136MEDIUM5.7ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because j...
CVE-2025-55135MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userCont...
CVE-2025-55134MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.
CVE-2025-55133MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManag...
CVE-2025-44779MEDIUM6.6An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/...
CVE-2025-50952MEDIUM6.5openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
CVE-2025-47188MEDIUM6.5A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th...
CVE-2025-8533MEDIUM6.9A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client author...
CVE-2025-32094MEDIUM4An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstan...
CVE-2025-8583MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform...
CVE-2025-8582MEDIUM4.3Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to ...
CVE-2025-8581MEDIUM4.3Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinc...
CVE-2025-8580MEDIUM4.3Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform...
CVE-2025-8579MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who...
CVE-2025-8577MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who...
CVE-2025-54885MEDIUM6.9Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. ...
CVE-2025-54798MEDIUM5.3tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrar...
CVE-2025-54784MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cro...
CVE-2025-54783MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-54786MEDIUM5.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-51058MEDIUM6.5Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/pr...
CVE-2025-51057MEDIUM6.5A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read a...
CVE-2025-51054MEDIUM6.5Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now