2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50157MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-50156MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-50154MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p...
CVE-2025-49755MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac...
CVE-2025-49751MEDIUM6.8Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2025-49745MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premi...
CVE-2025-49743MEDIUM6.7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-49736MEDIUM4.3The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over ...
CVE-2025-49707MEDIUM5.5Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
CVE-2025-49559MEDIUM5.3Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an...
CVE-2025-49558MEDIUM5.9Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ...
CVE-2025-48807MEDIUM6.7Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to ...
CVE-2025-25007MEDIUM5.3Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to pe...
CVE-2025-25006MEDIUM5.3Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform ...
CVE-2025-25005MEDIUM6.5Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network...
CVE-2025-20044MEDIUM5.6Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially ...
CVE-2025-55166MEDIUM5.1savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method...
CVE-2025-49568MEDIUM5.5Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclo...
CVE-2025-49567MEDIUM5.5Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...
CVE-2025-27717MEDIUM6.7Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl...
CVE-2025-27559MEDIUM6.7Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated use...
CVE-2025-27537MEDIUM5.5Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platfor...
CVE-2025-27250MEDIUM5.1Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge...
CVE-2025-26863MEDIUM4.8Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2...
CVE-2025-26697MEDIUM4.8Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now