2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12699MEDIUM6.7The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC...
CVE-2025-54514MEDIUM4.8Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po...
CVE-2025-52536MEDIUM6.7Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot...
CVE-2025-52534MEDIUM5.3Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting...
CVE-2025-48517MEDIUM4.6Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to ...
CVE-2025-48515MEDIUM5.4Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI...
CVE-2025-48514MEDIUM4Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a...
CVE-2025-29952MEDIUM5.9Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged atta...
CVE-2025-29949MEDIUM4.8Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al...
CVE-2025-29948MEDIUM5.9Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa...
CVE-2025-29946MEDIUM4.5Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent...
CVE-2025-29939MEDIUM6.9Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever...
CVE-2025-0031MEDIUM4.6A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK...
CVE-2025-0012MEDIUM6.8Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could...
CVE-2025-36522MEDIUM6.7Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:...
CVE-2025-36511MEDIUM6.7Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applica...
CVE-2025-35999MEDIUM6.7Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) S...
CVE-2025-35992MEDIUM5.7Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia...
CVE-2025-32735MEDIUM6.8Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia...
CVE-2025-32467MEDIUM5.6Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an informati...
CVE-2025-32453MEDIUM6.7Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an ...
CVE-2025-32452MEDIUM6.7Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an ...
CVE-2025-32092MEDIUM6.7Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Appli...
CVE-2025-32007MEDIUM5.6Out-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disc...
CVE-2025-32003MEDIUM6.5Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now