2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-29937MEDIUM5.8An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an...
CVE-2025-0044MEDIUM4.8An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l...
CVE-2025-0040MEDIUM5.3Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a...
CVE-2025-48521MEDIUM6.9Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft...
CVE-2025-48520MEDIUM6.9An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a...
CVE-2025-0045MEDIUM6.9Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove...
CVE-2025-64526MEDIUM5.3Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middlewa...
CVE-2025-62313MEDIUM5.4HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m...
CVE-2025-62311MEDIUM4.3HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. Th...
CVE-2025-62310MEDIUM5.4HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. T...
CVE-2025-62308MEDIUM5.1HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such ...
CVE-2025-62305MEDIUM5.1HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul...
CVE-2025-69443MEDIUM6.3Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru...
CVE-2025-62625MEDIUM6Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens...
CVE-2025-62619MEDIUM6.3Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex...
CVE-2025-15345MEDIUM6.1The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par...
CVE-2025-13874MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2025-12669MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an...
CVE-2025-27852MEDIUM5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack...
CVE-2025-32425MEDIUM5.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2025-29338MEDIUM5.6NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff...
CVE-2025-14767MEDIUM5.5The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2025-14033MEDIUM5.3The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-9989MEDIUM4.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-9988MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now