2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32094MEDIUM4An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstan...
CVE-2025-8583MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform...
CVE-2025-8582MEDIUM4.3Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to ...
CVE-2025-8581MEDIUM4.3Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinc...
CVE-2025-8580MEDIUM4.3Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform...
CVE-2025-8579MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who...
CVE-2025-8578HIGH8.8Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor...
CVE-2025-8577MEDIUM4.3Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who...
CVE-2025-8576HIGH8.8Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he...
CVE-2025-29865HIGH8.7: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade...
CVE-2025-54885MEDIUM6.9Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. ...
CVE-2025-54882HIGH7.1Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1....
CVE-2025-54799LOW2.3Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4...
CVE-2025-54798MEDIUM5.3tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrar...
CVE-2025-54784MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cro...
CVE-2025-54783MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-3770HIGH7EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes...
CVE-2025-54788HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an...
CVE-2025-54786MEDIUM5.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-54785HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7....
CVE-2025-8086Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-7770HIGH8.7Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are genera...
CVE-2025-7769HIGH8.7Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE...
CVE-2025-7768CRITICAL9.3Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain ...
CVE-2025-6634HIGH7.8A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now