2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13649 | MEDIUM | 6.1 | 0.2% | Feb 11, 2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not nec... |
| CVE-2025-13648 | MEDIUM | 6.1 | 0.2% | Feb 11, 2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is require... |
| CVE-2025-10913 | HIGH | 8.3 | 0.3% | Feb 11, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cl... |
| CVE-2025-10912 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikY... |
| CVE-2025-15400 | MEDIUM | 6.5 | 0.3% | Feb 11, 2026 | The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r... |
| CVE-2025-15524 | MEDIUM | 4.3 | 0.2% | Feb 11, 2026 | The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2025-14541 | HIGH | 7.2 | 0.5% | Feb 11, 2026 | The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin... |
| CVE-2025-13431 | MEDIUM | 6.5 | 0.2% | Feb 11, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve... |
| CVE-2025-12699 | MEDIUM | 6.7 | 0.2% | Feb 10, 2026 | The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC... |
| CVE-2025-54514 | MEDIUM | 4.8 | 0.1% | Feb 10, 2026 | Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po... |
| CVE-2025-52536 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot... |
| CVE-2025-52534 | MEDIUM | 5.3 | 0.3% | Feb 10, 2026 | Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting... |
| CVE-2025-48517 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to ... |
| CVE-2025-48515 | MEDIUM | 5.4 | 0.1% | Feb 10, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI... |
| CVE-2025-48514 | MEDIUM | 4 | 0.1% | Feb 10, 2026 | Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a... |
| CVE-2025-48509 | LOW | 1.8 | 0.1% | Feb 10, 2026 | Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m... |
| CVE-2025-29952 | MEDIUM | 5.9 | 0.1% | Feb 10, 2026 | Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged atta... |
| CVE-2025-29951 | HIGH | 7.3 | 0.1% | Feb 10, 2026 | A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially ... |
| CVE-2025-29950 | HIGH | 7.1 | 0.1% | Feb 10, 2026 | Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory le... |
| CVE-2025-29949 | MEDIUM | 4.8 | 0.1% | Feb 10, 2026 | Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al... |
| CVE-2025-29948 | MEDIUM | 5.9 | 0.1% | Feb 10, 2026 | Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa... |
| CVE-2025-29946 | MEDIUM | 4.5 | 0.1% | Feb 10, 2026 | Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent... |
| CVE-2025-29939 | MEDIUM | 6.9 | 0.1% | Feb 10, 2026 | Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever... |
| CVE-2025-0031 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK... |
| CVE-2025-0029 | LOW | 1.8 | 0.1% | Feb 10, 2026 | Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now