2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59429MEDIUM5.4FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior t...
CVE-2025-33177MEDIUM5.5NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all...
CVE-2025-54275MEDIUM5.5Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to...
CVE-2025-8459MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-60537MEDIUM6.5Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a...
CVE-2025-57563MEDIUM6.5A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to rea...
CVE-2025-8430MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-59497MEDIUM4.7Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny ...
CVE-2025-59294MEDIUM4.6Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di...
CVE-2025-59288MEDIUM5.3Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi...
CVE-2025-59284MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp...
CVE-2025-59260MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author...
CVE-2025-59259MEDIUM6.5Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d...
CVE-2025-59258MEDIUM6.2Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker...
CVE-2025-59257MEDIUM6.5Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d...
CVE-2025-59253MEDIUM5.5Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
CVE-2025-59244MEDIUM6.5External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n...
CVE-2025-59229MEDIUM5.5Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
CVE-2025-59214MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p...
CVE-2025-59211MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack...
CVE-2025-59209MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack...
CVE-2025-59204MEDIUM5.5Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information local...
CVE-2025-59203MEDIUM5.5Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclos...
CVE-2025-59198MEDIUM5Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
CVE-2025-59197MEDIUM5.5Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose inform...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now