2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27560MEDIUM6.7Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0: Kernel may allow a deni...
CVE-2025-27535MEDIUM4.1Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers...
CVE-2025-27243MEDIUM4.4Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring...
CVE-2025-24851MEDIUM4.4Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x withi...
CVE-2025-22885MEDIUM5.6Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software ad...
CVE-2025-22849MEDIUM6.7Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584...
CVE-2025-20106MEDIUM6.7Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolki...
CVE-2025-20070MEDIUM6.7Improper conditions check for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_02.00.00.4052, CR...
CVE-2025-70347MEDIUM5.5An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted...
CVE-2025-68686MEDIUM5.9An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS ...
CVE-2025-62439MEDIUM4.2An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS ...
CVE-2025-55018MEDIUM5.8An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, Fort...
CVE-2025-15572MEDIUM5.5A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation ...
CVE-2025-15571MEDIUM5.5A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompt...
CVE-2025-11537MEDIUM5A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre...
CVE-2025-14895MEDIUM5.4The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. Thi...
CVE-2025-12063MEDIUM5.7An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the...
CVE-2025-13064MEDIUM4.5A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w...
CVE-2025-12757MEDIUM4.6An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are n...
CVE-2025-15147MEDIUM4.3The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2025-15318MEDIUM6Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
CVE-2025-15317MEDIUM6.5Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.
CVE-2025-14778MEDIUM5.4A flaw was found in Keycloak. A significant Broken Access Control vulnerability exists in the UserManagedPermissionServi...
CVE-2025-63354MEDIUM4.8Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fail...
CVE-2025-59024MEDIUM6.5Crafted delegations or IP fragments can poison cached delegations in Recursor.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now