2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55338MEDIUM4.6Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with...
CVE-2025-55337MEDIUM4.6Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe...
CVE-2025-55336MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorize...
CVE-2025-55334MEDIUM5.5Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security featur...
CVE-2025-55333MEDIUM4.6Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security fea...
CVE-2025-55332MEDIUM4.6Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe...
CVE-2025-55330MEDIUM4.6Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe...
CVE-2025-55325MEDIUM5.5Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-55320MEDIUM6.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ...
CVE-2025-55248MEDIUM5.7Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose informat...
CVE-2025-48813MEDIUM4.7Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
CVE-2025-47979MEDIUM5.5Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i...
CVE-2025-37148MEDIUM6.5A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta...
CVE-2025-37145MEDIUM4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit...
CVE-2025-37144MEDIUM4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit...
CVE-2025-37143MEDIUM4.9An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/...
CVE-2025-37142MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37141MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37140MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37139MEDIUM6A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i...
CVE-2025-37138MEDIUM6.2An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Cont...
CVE-2025-37137MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37136MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37135MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-36730MEDIUM4.6A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now