2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24918 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software a... |
| CVE-2025-24863 | MEDIUM | 6.5 | 0.3% | Nov 11, 2025 | Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl... |
| CVE-2025-24848 | MEDIUM | 6.3 | 0.1% | Nov 11, 2025 | Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appli... |
| CVE-2025-24847 | MEDIUM | 5.7 | 0.3% | Nov 11, 2025 | Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicat... |
| CVE-2025-24842 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications m... |
| CVE-2025-24834 | MEDIUM | 6.5 | 0.2% | Nov 11, 2025 | Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appli... |
| CVE-2025-24519 | MEDIUM | 5.5 | 0.1% | Nov 11, 2025 | Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow ... |
| CVE-2025-24516 | MEDIUM | 6.8 | 0.2% | Nov 11, 2025 | Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicatio... |
| CVE-2025-24512 | MEDIUM | 5.7 | 0.1% | Nov 11, 2025 | Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring ... |
| CVE-2025-24491 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.146... |
| CVE-2025-24327 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ri... |
| CVE-2025-24314 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicatio... |
| CVE-2025-22391 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation ... |
| CVE-2025-20614 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: U... |
| CVE-2025-20065 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Devi... |
| CVE-2025-20056 | MEDIUM | 4.8 | 0.1% | Nov 11, 2025 | Improper input validation for some Intel VTune Profiler before version 2025.1 within Ring 3: User Applications may allow... |
| CVE-2025-20050 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicati... |
| CVE-2025-12940 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1... |
| CVE-2025-13013 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Fir... |
| CVE-2025-10905 | MEDIUM | 4.4 | 0.1% | Nov 11, 2025 | Collision in MiniFilter driver in Avast Software Avast Free Antivirus before 25.9 on Windows allows a local attacker w... |
| CVE-2025-9227 | MEDIUM | 6.5 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap pr... |
| CVE-2025-12101 | MEDIUM | 5.9 | 24.6% | Nov 11, 2025 | Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN vir... |
| CVE-2025-41106 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41105 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41104 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now