2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54101MEDIUM4.8Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
CVE-2025-54097MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54096MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54095MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54094MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53810MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53809MEDIUM6.5Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to...
CVE-2025-53808MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53806MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53804MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i...
CVE-2025-53803MEDIUM5.5Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose...
CVE-2025-53799MEDIUM5.5Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information local...
CVE-2025-53798MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53797MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53796MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53348MEDIUM5.3Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control S...
CVE-2025-53340MEDIUM5.3Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive...
CVE-2025-53291MEDIUM5.4Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a thro...
CVE-2025-49860MEDIUM5.3Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Su...
CVE-2025-47997MEDIUM5.3Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an auth...
CVE-2025-47437MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue af...
CVE-2025-39553MEDIUM4.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th...
CVE-2025-39541MEDIUM6.5Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affe...
CVE-2025-39523MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects...
CVE-2025-32688MEDIUM5.4Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Targ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now