2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55136MEDIUM5.7ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because j...
CVE-2025-55135MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userCont...
CVE-2025-55134MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.
CVE-2025-55133MEDIUM6.4In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManag...
CVE-2025-44779MEDIUM6.6An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/...
CVE-2025-50952MEDIUM6.5openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
CVE-2025-47188MEDIUM6.5A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th...
CVE-2025-8533MEDIUM6.9A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client author...
CVE-2025-32094MEDIUM4An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstan...
CVE-2025-8583MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform...
CVE-2025-8582MEDIUM4.3Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to ...
CVE-2025-8581MEDIUM4.3Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinc...
CVE-2025-8580MEDIUM4.3Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform...
CVE-2025-8579MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who...
CVE-2025-8577MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who...
CVE-2025-54885MEDIUM6.9Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. ...
CVE-2025-54798MEDIUM5.3tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrar...
CVE-2025-54784MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cro...
CVE-2025-54783MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-54786MEDIUM5.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-51058MEDIUM6.5Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/pr...
CVE-2025-51057MEDIUM6.5A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read a...
CVE-2025-51054MEDIUM6.5Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privi...
CVE-2025-51053MEDIUM6.1A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject...
CVE-2025-51052MEDIUM6.5A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now