2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32094 | MEDIUM | 4 | 0.5% | Aug 7, 2025 | An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstan... |
| CVE-2025-8583 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform... |
| CVE-2025-8582 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to ... |
| CVE-2025-8581 | MEDIUM | 4.3 | 0.3% | Aug 7, 2025 | Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinc... |
| CVE-2025-8580 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform... |
| CVE-2025-8579 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who... |
| CVE-2025-8578 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2025-8577 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who... |
| CVE-2025-8576 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he... |
| CVE-2025-29865 | HIGH | 8.7 | 0.4% | Aug 7, 2025 | : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade... |
| CVE-2025-54885 | MEDIUM | 6.9 | 0.4% | Aug 7, 2025 | Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. ... |
| CVE-2025-54882 | HIGH | 7.1 | 0.2% | Aug 7, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.... |
| CVE-2025-54799 | LOW | 2.3 | 0.2% | Aug 7, 2025 | Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4... |
| CVE-2025-54798 | MEDIUM | 5.3 | 0.3% | Aug 7, 2025 | tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrar... |
| CVE-2025-54784 | MEDIUM | 6.1 | 0.2% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cro... |
| CVE-2025-54783 | MEDIUM | 6.1 | 0.2% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.... |
| CVE-2025-3770 | HIGH | 7 | 0.1% | Aug 7, 2025 | EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes... |
| CVE-2025-54788 | HIGH | 8.8 | 0.4% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an... |
| CVE-2025-54786 | MEDIUM | 5.3 | 0.3% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.... |
| CVE-2025-54785 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.... |
| CVE-2025-8086 | — | — | — | Aug 6, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-7770 | HIGH | 8.7 | 0.5% | Aug 6, 2025 | Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are genera... |
| CVE-2025-7769 | HIGH | 8.7 | 16.2% | Aug 6, 2025 | Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE... |
| CVE-2025-7768 | CRITICAL | 9.3 | 0.5% | Aug 6, 2025 | Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain ... |
| CVE-2025-6634 | HIGH | 7.8 | 0.2% | Aug 6, 2025 | A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now