2025 CVE Vulnerabilities

45,180 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49539MEDIUM4.5ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-43584MEDIUM5.5Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2025-43583MEDIUM5.5Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ...
CVE-2025-48386MEDIUM6.3Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-27369MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a ...
CVE-2025-27367MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side v...
CVE-2025-7363MEDIUM5.4The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User i...
CVE-2025-7362MEDIUM5.4The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted ...
CVE-2025-53479MEDIUM5.4The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. T...
CVE-2025-4663MEDIUM4.9An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow ...
CVE-2025-47135MEDIUM5.5Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure o...
CVE-2025-53513MEDIUM6.5The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on t...
CVE-2025-53512MEDIUM6.5The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb...
CVE-2025-49722MEDIUM5.7Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over...
CVE-2025-49706MEDIUM6.5Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ...
CVE-2025-49684MEDIUM5.5Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVE-2025-49681MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-49671MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an...
CVE-2025-49670MEDIUM6.5Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49664MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authoriz...
CVE-2025-49658MEDIUM5.5Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
CVE-2025-48823MEDIUM5.9Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a ne...
CVE-2025-48818MEDIUM6.8Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur...
CVE-2025-48812MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-48811MEDIUM6.7Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now