2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48810MEDIUM5.5Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authori...
CVE-2025-48809MEDIUM5.5Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker...
CVE-2025-48808MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i...
CVE-2025-48804MEDIUM6.8Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass...
CVE-2025-48803MEDIUM6.7Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker...
CVE-2025-48802MEDIUM6.5Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
CVE-2025-48800MEDIUM6.8Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2025-48003MEDIUM6.8Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2025-48002MEDIUM5.7Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent...
CVE-2025-48001MEDIUM6.8Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur...
CVE-2025-47999MEDIUM6.8Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2025-47980MEDIUM6.2Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker ...
CVE-2025-47978MEDIUM6.5Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
CVE-2025-47109MEDIUM5.5After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...
CVE-2025-43587MEDIUM5.5After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-43580MEDIUM5.5Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit...
CVE-2025-26636MEDIUM5.5Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker...
CVE-2025-21195MEDIUM6Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat...
CVE-2025-21168MEDIUM5.5Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2025-21167MEDIUM5.5Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2025-5464MEDIUM5.5Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe...
CVE-2025-0292MEDIUM4.9SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a...
CVE-2025-7182MEDIUM6.1A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A...
CVE-2025-5463MEDIUM5.5Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se...
CVE-2025-5451MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now