2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54188MEDIUM5.5Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2025-54186MEDIUM5.5Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2025-49562MEDIUM5.5Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could lead to disclosur...
CVE-2025-36000MEDIUM4.8IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This ...
CVE-2025-55169MEDIUM6.5WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio...
CVE-2025-47857MEDIUM6.7A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F...
CVE-2025-43734MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-32932MEDIUM5.4An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiS...
CVE-2025-32766MEDIUM6.7A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7....
CVE-2025-27759MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2025-25248MEDIUM6.5An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, v...
CVE-2025-53781MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to di...
CVE-2025-53769MEDIUM5.5External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVE-2025-53765MEDIUM5.5Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclo...
CVE-2025-53736MEDIUM6.2Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2025-53728MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize...
CVE-2025-53719MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-53716MEDIUM6.5Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to ...
CVE-2025-53156MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to discl...
CVE-2025-53153MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-53148MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-53138MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-53136MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disc...
CVE-2025-50172MEDIUM6.5Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service ov...
CVE-2025-50166MEDIUM6.5Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now