2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48002MEDIUM5.7Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent...
CVE-2025-48001MEDIUM6.8Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur...
CVE-2025-47999MEDIUM6.8Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2025-47980MEDIUM6.2Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker ...
CVE-2025-47978MEDIUM6.5Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
CVE-2025-47109MEDIUM5.5After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...
CVE-2025-43587MEDIUM5.5After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-43580MEDIUM5.5Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit...
CVE-2025-26636MEDIUM5.5Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker...
CVE-2025-21195MEDIUM6Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat...
CVE-2025-21168MEDIUM5.5Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2025-21167MEDIUM5.5Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ...
CVE-2025-5464MEDIUM5.5Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe...
CVE-2025-0292MEDIUM4.9SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a...
CVE-2025-7182MEDIUM6.1A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A...
CVE-2025-5463MEDIUM5.5Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se...
CVE-2025-5451MEDIUM4.9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 2...
CVE-2025-53545MEDIUM6.9Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2025-53480MEDIUM5.4The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific in...
CVE-2025-3630MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug...
CVE-2025-2827MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installat...
CVE-2025-2793MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug...
CVE-2025-29267MEDIUM6.5SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to ob...
CVE-2025-21433MEDIUM5.5Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-40721MEDIUM5.4Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now