2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65954MEDIUM6.1SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel...
CVE-2025-57282HIGH8.8ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-56352HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri...
CVE-2025-4202MEDIUM4.3The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo...
CVE-2025-67031MEDIUM6.3ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera...
CVE-2025-67437MEDIUM6.5Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a...
CVE-2025-14972MEDIUM4.1* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually...
CVE-2025-54518HIGH7Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to...
CVE-2025-52532LOW2A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the globa...
CVE-2025-66664MEDIUM4.6Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf...
CVE-2025-66660LOW1.8Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2025-54517HIGH8.5Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via rem...
CVE-2025-54511MEDIUM5.3Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp...
CVE-2025-48516MEDIUM6.9Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc...
CVE-2025-48513MEDIUM6.9Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini...
CVE-2025-29944MEDIUM6.8A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p...
CVE-2025-29938HIGH7.1An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi...
CVE-2025-29937MEDIUM5.8An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an...
CVE-2025-29936HIGH8.4Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ...
CVE-2025-29935HIGH8.4An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c...
CVE-2025-0044MEDIUM4.8An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l...
CVE-2025-0040MEDIUM5.3Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a...
CVE-2025-0028HIGH8.3An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ...
CVE-2025-52540HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a...
CVE-2025-48521MEDIUM6.9Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now