2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30405 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their alloc... |
| CVE-2025-30404 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially res... |
| CVE-2025-54787 | LOW | 3.7 | 0.2% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vul... |
| CVE-2025-8701 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic... |
| CVE-2025-8698 | LOW | 3.3 | 0.2% | Aug 7, 2025 | A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_ns... |
| CVE-2025-53792 | CRITICAL | 9.1 | 0.7% | Aug 7, 2025 | Azure Portal Elevation of Privilege Vulnerability |
| CVE-2025-53787 | HIGH | 7.5 | 0.6% | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-53774 | HIGH | 7.5 | 0.5% | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-53767 | CRITICAL | 10 | 1.0% | Aug 7, 2025 | Azure OpenAI Elevation of Privilege Vulnerability |
| CVE-2025-45765 | CRITICAL | 9.1 | 0.2% | Aug 7, 2025 | ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not som... |
| CVE-2025-26513 | HIGH | 7.8 | 0.1% | Aug 7, 2025 | The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ... |
| CVE-2025-48709 | HIGH | 7.8 | 0.1% | Aug 7, 2025 | BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta... |
| CVE-2025-47808 | MEDIUM | 5.6 | 0.4% | Aug 7, 2025 | In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par... |
| CVE-2025-47807 | MEDIUM | 5.5 | 0.2% | Aug 7, 2025 | In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh... |
| CVE-2025-47806 | MEDIUM | 5.6 | 0.3% | Aug 7, 2025 | In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack ... |
| CVE-2025-47219 | HIGH | 8.1 | 0.6% | Aug 7, 2025 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil... |
| CVE-2025-47183 | MEDIUM | 6.6 | 0.2% | Aug 7, 2025 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil... |
| CVE-2025-8697 | MEDIUM | 6.3 | 2.2% | Aug 7, 2025 | A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi... |
| CVE-2025-7195 | MEDIUM | 6.4 | 0.2% | Aug 7, 2025 | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used... |
| CVE-2025-55077 | HIGH | 7.4 | 0.2% | Aug 7, 2025 | Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s... |
| CVE-2025-51533 | MEDIUM | 5.3 | 0.3% | Aug 7, 2025 | An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in... |
| CVE-2025-50692 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html. |
| CVE-2025-50675 | HIGH | 7.8 | 0.2% | Aug 7, 2025 | GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati... |
| CVE-2025-51629 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker... |
| CVE-2025-55138 | HIGH | 7.4 | 0.3% | Aug 7, 2025 | LinkJoin through 882f196 mishandles token ownership in password reset. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now