2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48514MEDIUM4Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to a...
CVE-2025-29952MEDIUM5.9Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged atta...
CVE-2025-29949MEDIUM4.8Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could al...
CVE-2025-29948MEDIUM5.9Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypa...
CVE-2025-29946MEDIUM4.5Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent...
CVE-2025-29939MEDIUM6.9Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever...
CVE-2025-0031MEDIUM4.6A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCK...
CVE-2025-0012MEDIUM6.8Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could...
CVE-2025-36522MEDIUM6.7Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3:...
CVE-2025-36511MEDIUM6.7Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applica...
CVE-2025-35999MEDIUM6.7Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) S...
CVE-2025-35992MEDIUM5.7Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia...
CVE-2025-32735MEDIUM6.8Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia...
CVE-2025-32467MEDIUM5.6Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an informati...
CVE-2025-32453MEDIUM6.7Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an ...
CVE-2025-32452MEDIUM6.7Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an ...
CVE-2025-32092MEDIUM6.7Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0 within Ring 3: User Appli...
CVE-2025-32007MEDIUM5.6Out-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disc...
CVE-2025-32003MEDIUM6.5Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, c...
CVE-2025-31944MEDIUM5.6Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Author...
CVE-2025-31655MEDIUM6.7Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow ...
CVE-2025-30508MEDIUM6.8Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may all...
CVE-2025-27940MEDIUM5.6Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosu...
CVE-2025-27708MEDIUM5.6Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) withi...
CVE-2025-27572MEDIUM5.6Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an informa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now