2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47972HIGH8Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed...
CVE-2025-47971HIGH7.8Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47178HIGH8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ...
CVE-2025-47159HIGH7.8Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele...
CVE-2025-47109MEDIUM5.5After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...
CVE-2025-43587MEDIUM5.5After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-43580MEDIUM5.5Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit...
CVE-2025-33054HIGH8.1Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo...
CVE-2025-26636MEDIUM5.5Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker...
CVE-2025-21195MEDIUM6Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat...
CVE-2025-21168MEDIUM5.5Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2025-21167MEDIUM5.5Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2025-21166HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-21165HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-21164HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-7185CRITICAL9.8A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. This vulnerability affe...
CVE-2025-7184CRITICAL9.8A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. This affects an unkno...
CVE-2025-6771HIGH7.2OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re...
CVE-2025-5464MEDIUM5.5Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe...
CVE-2025-43019HIGH7.8A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc...
CVE-2025-3648HIGH8.2A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. ...
CVE-2025-0293LOW2.7CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows ...
CVE-2025-0292MEDIUM4.9SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a...
CVE-2025-7326HIGH7Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi...
CVE-2025-7183CRITICAL9.8A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now