2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65954 | MEDIUM | 6.1 | 0.3% | May 18, 2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel... |
| CVE-2025-57282 | HIGH | 8.8 | 1.0% | May 18, 2026 | ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. |
| CVE-2025-56352 | HIGH | 7.5 | 0.3% | May 18, 2026 | In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri... |
| CVE-2025-4202 | MEDIUM | 4.3 | 0.2% | May 16, 2026 | The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo... |
| CVE-2025-67031 | MEDIUM | 6.3 | 0.3% | May 15, 2026 | ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera... |
| CVE-2025-67437 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a... |
| CVE-2025-14972 | MEDIUM | 4.1 | 0.1% | May 15, 2026 | * Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually... |
| CVE-2025-54518 | HIGH | 7 | 0.3% | May 15, 2026 | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to... |
| CVE-2025-52532 | LOW | 2 | 0.1% | May 15, 2026 | A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa... |
| CVE-2025-66664 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf... |
| CVE-2025-66660 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2025-54517 | HIGH | 8.5 | 0.1% | May 15, 2026 | Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem... |
| CVE-2025-54511 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp... |
| CVE-2025-48516 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc... |
| CVE-2025-48513 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini... |
| CVE-2025-29944 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p... |
| CVE-2025-29938 | HIGH | 7.1 | 0.1% | May 15, 2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi... |
| CVE-2025-29937 | MEDIUM | 5.8 | 0.1% | May 15, 2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an... |
| CVE-2025-29936 | HIGH | 8.4 | 0.1% | May 15, 2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ... |
| CVE-2025-29935 | HIGH | 8.4 | 0.1% | May 15, 2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c... |
| CVE-2025-0044 | MEDIUM | 4.8 | 0.1% | May 15, 2026 | An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l... |
| CVE-2025-0040 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a... |
| CVE-2025-0028 | HIGH | 8.3 | 0.1% | May 15, 2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ... |
| CVE-2025-52540 | HIGH | 8.5 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a... |
| CVE-2025-48521 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now