2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47986HIGH8.8Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47985HIGH7.8Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
CVE-2025-47984HIGH7.5Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
CVE-2025-47982HIGH7.8Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-47976HIGH7.8Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47975HIGH7Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47973HIGH7.8Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47972HIGH8Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed...
CVE-2025-47971HIGH7.8Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47178HIGH8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ...
CVE-2025-47159HIGH7.8Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele...
CVE-2025-33054HIGH8.1Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo...
CVE-2025-21166HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-21165HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-21164HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-6771HIGH7.2OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re...
CVE-2025-43019HIGH7.8A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc...
CVE-2025-3648HIGH8.2A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. ...
CVE-2025-7326HIGH7Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi...
CVE-2025-7037HIGH7.2SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti...
CVE-2025-6996HIGH8.4Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update ...
CVE-2025-6995HIGH8.4Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update ...
CVE-2025-6770HIGH7.2OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated atta...
CVE-2025-53372HIGH7.5node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to exe...
CVE-2025-36600HIGH8.2Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now