2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31944 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Author... |
| CVE-2025-31655 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow ... |
| CVE-2025-30508 | MEDIUM | 6.8 | 0.1% | Feb 10, 2026 | Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may all... |
| CVE-2025-27940 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosu... |
| CVE-2025-27708 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) withi... |
| CVE-2025-27572 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an informa... |
| CVE-2025-27560 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0: Kernel may allow a deni... |
| CVE-2025-27535 | MEDIUM | 4.1 | 0.1% | Feb 10, 2026 | Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers... |
| CVE-2025-27243 | MEDIUM | 4.4 | 0.1% | Feb 10, 2026 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring... |
| CVE-2025-24851 | MEDIUM | 4.4 | 0.1% | Feb 10, 2026 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x withi... |
| CVE-2025-22885 | MEDIUM | 5.6 | 0.1% | Feb 10, 2026 | Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software ad... |
| CVE-2025-22849 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584... |
| CVE-2025-20106 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolki... |
| CVE-2025-20070 | MEDIUM | 6.7 | 0.1% | Feb 10, 2026 | Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR... |
| CVE-2025-70347 | MEDIUM | 5.5 | 0.1% | Feb 10, 2026 | An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted... |
| CVE-2025-68686 | MEDIUM | 5.9 | 0.5% | Feb 10, 2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS ... |
| CVE-2025-62439 | MEDIUM | 4.2 | 0.1% | Feb 10, 2026 | An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS ... |
| CVE-2025-55018 | MEDIUM | 5.8 | 0.4% | Feb 10, 2026 | An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, Fort... |
| CVE-2025-15572 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation ... |
| CVE-2025-15571 | MEDIUM | 5.5 | 0.2% | Feb 10, 2026 | A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompt... |
| CVE-2025-11537 | MEDIUM | 5 | 0.1% | Feb 10, 2026 | A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre... |
| CVE-2025-14895 | MEDIUM | 5.4 | 0.3% | Feb 10, 2026 | The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi... |
| CVE-2025-12063 | MEDIUM | 5.7 | 0.2% | Feb 10, 2026 | An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the... |
| CVE-2025-13064 | MEDIUM | 4.5 | 0.2% | Feb 10, 2026 | A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w... |
| CVE-2025-12757 | MEDIUM | 4.6 | 0.3% | Feb 10, 2026 | An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are n... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now