2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30327HIGH7.8InCopy versions 20.2, 19.5.3 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resu...
CVE-2025-5971HIGH8.8A vulnerability was found in code-projects School Fees Payment System 1.0. It has been classified as critical. This affe...
CVE-2025-5943HIGH8.8MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this i...
CVE-2025-43588HIGH7.8Substance3D - Sampler versions 5.0 and earlier are affected by an out-of-bounds write vulnerability that could result in...
CVE-2025-43581HIGH7.8Substance3D - Sampler versions 5.0 and earlier are affected by an out-of-bounds write vulnerability that could result in...
CVE-2025-36580MEDIUM4.8Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Gener...
CVE-2025-36578MEDIUM6.8Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privilege...
CVE-2025-36577MEDIUM6.1Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Gener...
CVE-2025-36576LOW2.7Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high...
CVE-2025-36575HIGH7.5Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries...
CVE-2025-36574HIGH8.2Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthentica...
CVE-2025-2884MEDIUM6.6TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack ...
CVE-2025-2474CRITICAL9.8Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ...
CVE-2025-0052HIGH8.3Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Ser...
CVE-2025-0051HIGH8.7Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Ser...
CVE-2025-5970MEDIUM5.4A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by t...
CVE-2025-5969HIGH8.8A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is ...
CVE-2025-47977HIGH8.2Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platfo...
CVE-2025-47969MEDIUM4.4Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose in...
CVE-2025-47968HIGH7.8Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-47962HIGH7.8Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
CVE-2025-47957HIGH8.4Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47956MEDIUM5.5External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVE-2025-47955HIGH7.8Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi...
CVE-2025-47953HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now