2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47986 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47985 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47984 | HIGH | 7.5 | 14.3% | Jul 8, 2025 | Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-47982 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47976 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47975 | HIGH | 7 | 0.3% | Jul 8, 2025 | Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47973 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47972 | HIGH | 8 | 0.5% | Jul 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed... |
| CVE-2025-47971 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47178 | HIGH | 8 | 2.0% | Jul 8, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ... |
| CVE-2025-47159 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele... |
| CVE-2025-33054 | HIGH | 8.1 | 0.8% | Jul 8, 2025 | Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo... |
| CVE-2025-21166 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-21165 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-21164 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-6771 | HIGH | 7.2 | 14.8% | Jul 8, 2025 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re... |
| CVE-2025-43019 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc... |
| CVE-2025-3648 | HIGH | 8.2 | 1.7% | Jul 8, 2025 | A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. ... |
| CVE-2025-7326 | HIGH | 7 | 0.6% | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi... |
| CVE-2025-7037 | HIGH | 7.2 | 0.9% | Jul 8, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti... |
| CVE-2025-6996 | HIGH | 8.4 | 0.2% | Jul 8, 2025 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update ... |
| CVE-2025-6995 | HIGH | 8.4 | 0.2% | Jul 8, 2025 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update ... |
| CVE-2025-6770 | HIGH | 7.2 | 12.3% | Jul 8, 2025 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated atta... |
| CVE-2025-53372 | HIGH | 7.5 | 1.1% | Jul 8, 2025 | node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to exe... |
| CVE-2025-36600 | HIGH | 8.2 | 0.2% | Jul 8, 2025 | Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerabilit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now