2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12699 | MEDIUM | 6.7 | 0.2% | Feb 10, 2026 | The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC... |
| CVE-2025-54514 | MEDIUM | 4.8 | 0.1% | Feb 10, 2026 | Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po... |
| CVE-2025-52536 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot... |
| CVE-2025-52534 | MEDIUM | 5.3 | 0.3% | Feb 10, 2026 | Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting... |
| CVE-2025-48517 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to ... |
| CVE-2025-48515 | MEDIUM | 5.4 | 0.1% | Feb 10, 2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI... |
| CVE-2025-48514 | MEDIUM | 4 | 0.1% | Feb 10, 2026 | Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a... |
| CVE-2025-29952 | MEDIUM | 5.9 | 0.1% | Feb 10, 2026 | Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged atta... |
| CVE-2025-29949 | MEDIUM | 4.8 | 0.1% | Feb 10, 2026 | Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al... |
| CVE-2025-29948 | MEDIUM | 5.9 | 0.1% | Feb 10, 2026 | Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa... |
| CVE-2025-29946 | MEDIUM | 4.5 | 0.1% | Feb 10, 2026 | Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent... |
| CVE-2025-29939 | MEDIUM | 6.9 | 0.1% | Feb 10, 2026 | Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever... |
| CVE-2025-0031 | MEDIUM | 4.6 | 0.1% | Feb 10, 2026 | A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK... |
| CVE-2025-0012 | MEDIUM | 6.8 | 0.1% | Feb 10, 2026 | Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could... |
| CVE-2025-36522 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:... |
| CVE-2025-36511 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applica... |
| CVE-2025-35999 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) S... |
| CVE-2025-35992 | MEDIUM | 5.7 | 0.1% | Feb 10, 2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia... |
| CVE-2025-32735 | MEDIUM | 6.8 | 0.1% | Feb 10, 2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia... |
| CVE-2025-32467 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an informati... |
| CVE-2025-32453 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an ... |
| CVE-2025-32452 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an ... |
| CVE-2025-32092 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Appli... |
| CVE-2025-32007 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Out-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disc... |
| CVE-2025-32003 | MEDIUM | 6.5 | 0.2% | Feb 10, 2026 | Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now