2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48520 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-48519 | HIGH | 8.5 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-48512 | HIGH | 7 | 0.1% | May 15, 2026 | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c... |
| CVE-2025-0045 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove... |
| CVE-2025-64526 | MEDIUM | 5.3 | 0.5% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middlewa... |
| CVE-2025-15024 | HIGH | 8.8 | 0.2% | May 14, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Tra... |
| CVE-2025-15023 | HIGH | 8.8 | 0.2% | May 14, 2026 | Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Indus... |
| CVE-2025-62317 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive... |
| CVE-2025-62316 | LOW | 2.3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured... |
| CVE-2025-62313 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m... |
| CVE-2025-62312 | LOW | 3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho... |
| CVE-2025-62311 | MEDIUM | 4.3 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. Th... |
| CVE-2025-62310 | MEDIUM | 5.4 | 0.0% | May 14, 2026 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. T... |
| CVE-2025-62309 | LOW | 2.6 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may ... |
| CVE-2025-62308 | MEDIUM | 5.1 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such ... |
| CVE-2025-62305 | MEDIUM | 5.1 | 0.1% | May 14, 2026 | HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resul... |
| CVE-2025-69443 | MEDIUM | 6.3 | 0.3% | May 14, 2026 | Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, ru... |
| CVE-2025-62628 | HIGH | 7 | 0.1% | May 14, 2026 | Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a mali... |
| CVE-2025-62625 | MEDIUM | 6 | 0.2% | May 14, 2026 | Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sens... |
| CVE-2025-62619 | MEDIUM | 6.3 | 0.3% | May 14, 2026 | Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex... |
| CVE-2025-15025 | HIGH | 8.8 | 0.3% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and... |
| CVE-2025-12008 | HIGH | 8.8 | 0.2% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Med... |
| CVE-2025-68421 | HIGH | 8.7 | 0.2% | May 14, 2026 | Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. I... |
| CVE-2025-68420 | HIGH | 7.5 | 0.1% | May 14, 2026 | Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to... |
| CVE-2025-11024 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now