2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27560MEDIUM6.7Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0: Kernel may allow a deni...
CVE-2025-27535MEDIUM4.1Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers...
CVE-2025-27243MEDIUM4.4Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring...
CVE-2025-25210HIGH8.2Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User ...
CVE-2025-25058LOW3.3Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es...
CVE-2025-24851MEDIUM4.4Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x withi...
CVE-2025-22885MEDIUM5.6Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software ad...
CVE-2025-22849MEDIUM6.7Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584...
CVE-2025-22453HIGH7.5Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User ...
CVE-2025-20106MEDIUM6.7Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolki...
CVE-2025-20080HIGH8.2Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel...
CVE-2025-20070MEDIUM6.7Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR...
CVE-2025-70347MEDIUM5.5An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted...
CVE-2025-68686MEDIUM5.9An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS ...
CVE-2025-64157HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 throug...
CVE-2025-62676HIGH7.1An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet Forti...
CVE-2025-62439MEDIUM4.2An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS ...
CVE-2025-55018MEDIUM5.8An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, Fort...
CVE-2025-52436CRITICAL9.6An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-15572MEDIUM5.5A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation ...
CVE-2025-11004HIGH7.5The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. Th...
CVE-2025-7636HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security S...
CVE-2025-7347HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Trackin...
CVE-2025-15571MEDIUM5.5A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompt...
CVE-2025-6967HIGH8.7Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now