2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13649MEDIUM6.1An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not nec...
CVE-2025-13648MEDIUM6.1An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is require...
CVE-2025-10913HIGH8.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cl...
CVE-2025-10912MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikY...
CVE-2025-15400MEDIUM6.5The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r...
CVE-2025-15524MEDIUM4.3The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2025-14541HIGH7.2The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin...
CVE-2025-13431MEDIUM6.5The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve...
CVE-2025-12699MEDIUM6.7The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC...
CVE-2025-54514MEDIUM4.8Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po...
CVE-2025-52536MEDIUM6.7Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot...
CVE-2025-52534MEDIUM5.3Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting...
CVE-2025-48517MEDIUM4.6Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to ...
CVE-2025-48515MEDIUM5.4Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI...
CVE-2025-48514MEDIUM4Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a...
CVE-2025-48509LOW1.8Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m...
CVE-2025-29952MEDIUM5.9Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged atta...
CVE-2025-29951HIGH7.3A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially ...
CVE-2025-29950HIGH7.1Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le...
CVE-2025-29949MEDIUM4.8Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al...
CVE-2025-29948MEDIUM5.9Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa...
CVE-2025-29946MEDIUM4.5Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent...
CVE-2025-29939MEDIUM6.9Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever...
CVE-2025-0031MEDIUM4.6A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK...
CVE-2025-0029LOW1.8Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now