2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48810 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authori... |
| CVE-2025-48809 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker... |
| CVE-2025-48808 | MEDIUM | 5.5 | 0.5% | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i... |
| CVE-2025-48804 | MEDIUM | 6.8 | 0.5% | Jul 8, 2025 | Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass... |
| CVE-2025-48803 | MEDIUM | 6.7 | 0.3% | Jul 8, 2025 | Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker... |
| CVE-2025-48802 | MEDIUM | 6.5 | 0.7% | Jul 8, 2025 | Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. |
| CVE-2025-48800 | MEDIUM | 6.8 | 0.5% | Jul 8, 2025 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph... |
| CVE-2025-48003 | MEDIUM | 6.8 | 0.5% | Jul 8, 2025 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph... |
| CVE-2025-48002 | MEDIUM | 5.7 | 0.5% | Jul 8, 2025 | Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent... |
| CVE-2025-48001 | MEDIUM | 6.8 | 0.4% | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur... |
| CVE-2025-47999 | MEDIUM | 6.8 | 0.4% | Jul 8, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
| CVE-2025-47980 | MEDIUM | 6.2 | 0.6% | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker ... |
| CVE-2025-47978 | MEDIUM | 6.5 | 1.9% | Jul 8, 2025 | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
| CVE-2025-47109 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead... |
| CVE-2025-43587 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-43580 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit... |
| CVE-2025-26636 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker... |
| CVE-2025-21195 | MEDIUM | 6 | 0.3% | Jul 8, 2025 | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat... |
| CVE-2025-21168 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2025-21167 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2025-5464 | MEDIUM | 5.5 | 0.3% | Jul 8, 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe... |
| CVE-2025-0292 | MEDIUM | 4.9 | 0.6% | Jul 8, 2025 | SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a... |
| CVE-2025-7182 | MEDIUM | 6.1 | 0.3% | Jul 8, 2025 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A... |
| CVE-2025-5463 | MEDIUM | 5.5 | 0.3% | Jul 8, 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se... |
| CVE-2025-5451 | MEDIUM | 4.9 | 0.7% | Jul 8, 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 2... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now