2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54518 | HIGH | 7.3 | 0.3% | May 15, 2026 | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to... |
| CVE-2025-52532 | LOW | 2 | 0.1% | May 15, 2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa... |
| CVE-2025-66664 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf... |
| CVE-2025-66660 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2025-54517 | HIGH | 8.5 | 0.1% | May 15, 2026 | Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem... |
| CVE-2025-54511 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp... |
| CVE-2025-48516 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc... |
| CVE-2025-48513 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini... |
| CVE-2025-29944 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p... |
| CVE-2025-29938 | HIGH | 7.1 | 0.1% | May 15, 2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi... |
| CVE-2025-29937 | MEDIUM | 5.8 | 0.1% | May 15, 2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an... |
| CVE-2025-29936 | HIGH | 8.4 | 0.1% | May 15, 2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ... |
| CVE-2025-29935 | HIGH | 8.4 | 0.1% | May 15, 2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c... |
| CVE-2025-0044 | MEDIUM | 4.8 | 0.1% | May 15, 2026 | An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l... |
| CVE-2025-0040 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a... |
| CVE-2025-0028 | HIGH | 8.3 | 0.1% | May 15, 2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ... |
| CVE-2025-52540 | HIGH | 8.5 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a... |
| CVE-2025-48521 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft... |
| CVE-2025-48520 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-48519 | HIGH | 8.5 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-48512 | HIGH | 7 | 0.1% | May 15, 2026 | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c... |
| CVE-2025-0045 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove... |
| CVE-2025-64526 | MEDIUM | 5.3 | 0.5% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middlewa... |
| CVE-2025-15024 | HIGH | 8.8 | 0.2% | May 14, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra... |
| CVE-2025-15023 | HIGH | 8.8 | 0.2% | May 14, 2026 | Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Indus... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now