2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29937 | MEDIUM | 5.8 | 0.1% | May 15, 2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an... |
| CVE-2025-0044 | MEDIUM | 4.8 | 0.1% | May 15, 2026 | An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l... |
| CVE-2025-0040 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a... |
| CVE-2025-48521 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft... |
| CVE-2025-48520 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-0045 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove... |
| CVE-2025-64526 | MEDIUM | 5.3 | 0.5% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middlewa... |
| CVE-2025-62313 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m... |
| CVE-2025-62311 | MEDIUM | 4.3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. Th... |
| CVE-2025-62310 | MEDIUM | 5.4 | 0.0% | May 14, 2026 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. T... |
| CVE-2025-62308 | MEDIUM | 5.1 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such ... |
| CVE-2025-62305 | MEDIUM | 5.1 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul... |
| CVE-2025-69443 | MEDIUM | 6.3 | 0.3% | May 14, 2026 | Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru... |
| CVE-2025-62625 | MEDIUM | 6 | 0.2% | May 14, 2026 | Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens... |
| CVE-2025-62619 | MEDIUM | 6.3 | 0.3% | May 14, 2026 | Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex... |
| CVE-2025-15345 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par... |
| CVE-2025-13874 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-12669 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2025-27852 | MEDIUM | 5 | 0.1% | May 13, 2026 | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack... |
| CVE-2025-32425 | MEDIUM | 5.5 | 0.2% | May 13, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2025-29338 | MEDIUM | 5.6 | 0.2% | May 13, 2026 | NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff... |
| CVE-2025-14767 | MEDIUM | 5.5 | 0.2% | May 13, 2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text... |
| CVE-2025-14033 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi... |
| CVE-2025-9989 | MEDIUM | 4.4 | 0.2% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2025-9988 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now