2025 CVE Vulnerabilities
45,259 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47972 | HIGH | 8 | 0.5% | Jul 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed... |
| CVE-2025-47971 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47178 | HIGH | 8 | 2.0% | Jul 8, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ... |
| CVE-2025-47159 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele... |
| CVE-2025-47109 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead... |
| CVE-2025-43587 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-43580 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit... |
| CVE-2025-33054 | HIGH | 8.1 | 0.8% | Jul 8, 2025 | Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo... |
| CVE-2025-26636 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker... |
| CVE-2025-21195 | MEDIUM | 6 | 0.3% | Jul 8, 2025 | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat... |
| CVE-2025-21168 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2025-21167 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2025-21166 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-21165 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-21164 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-7185 | CRITICAL | 9.8 | 0.4% | Jul 8, 2025 | A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. This vulnerability affe... |
| CVE-2025-7184 | CRITICAL | 9.8 | 0.4% | Jul 8, 2025 | A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. This affects an unkno... |
| CVE-2025-6771 | HIGH | 7.2 | 14.8% | Jul 8, 2025 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re... |
| CVE-2025-5464 | MEDIUM | 5.5 | 0.3% | Jul 8, 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe... |
| CVE-2025-43019 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc... |
| CVE-2025-3648 | HIGH | 8.2 | 1.7% | Jul 8, 2025 | A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. ... |
| CVE-2025-0293 | LOW | 2.7 | 0.4% | Jul 8, 2025 | CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows ... |
| CVE-2025-0292 | MEDIUM | 4.9 | 0.6% | Jul 8, 2025 | SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a... |
| CVE-2025-7326 | HIGH | 7 | 0.6% | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi... |
| CVE-2025-7183 | CRITICAL | 9.8 | 0.4% | Jul 8, 2025 | A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now