2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30405CRITICAL9.8An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their alloc...
CVE-2025-30404CRITICAL9.8An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially res...
CVE-2025-54787LOW3.7SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vul...
CVE-2025-8701HIGH8.8A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic...
CVE-2025-8698LOW3.3A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_ns...
CVE-2025-53792CRITICAL9.1Azure Portal Elevation of Privilege Vulnerability
CVE-2025-53787HIGH7.5Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53774HIGH7.5Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53767CRITICAL10Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-45765CRITICAL9.1ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not som...
CVE-2025-26513HIGH7.8The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ...
CVE-2025-48709HIGH7.8BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta...
CVE-2025-47808MEDIUM5.6In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par...
CVE-2025-47807MEDIUM5.5In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh...
CVE-2025-47806MEDIUM5.6In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack ...
CVE-2025-47219HIGH8.1In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil...
CVE-2025-47183MEDIUM6.6In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil...
CVE-2025-8697MEDIUM6.3A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi...
CVE-2025-7195MEDIUM6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used...
CVE-2025-55077HIGH7.4Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s...
CVE-2025-51533MEDIUM5.3An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in...
CVE-2025-50692CRITICAL9.8FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
CVE-2025-50675HIGH7.8GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati...
CVE-2025-51629HIGH8.8A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker...
CVE-2025-55138HIGH7.4LinkJoin through 882f196 mishandles token ownership in password reset.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now