2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48002 | MEDIUM | 5.7 | 0.5% | Jul 8, 2025 | Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent... |
| CVE-2025-48001 | MEDIUM | 6.8 | 0.4% | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur... |
| CVE-2025-47999 | MEDIUM | 6.8 | 0.4% | Jul 8, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
| CVE-2025-47980 | MEDIUM | 6.2 | 0.6% | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker ... |
| CVE-2025-47978 | MEDIUM | 6.5 | 1.9% | Jul 8, 2025 | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
| CVE-2025-47109 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead... |
| CVE-2025-43587 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to d... |
| CVE-2025-43580 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerabilit... |
| CVE-2025-26636 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker... |
| CVE-2025-21195 | MEDIUM | 6 | 0.3% | Jul 8, 2025 | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevat... |
| CVE-2025-21168 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2025-21167 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2025-5464 | MEDIUM | 5.5 | 0.3% | Jul 8, 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe... |
| CVE-2025-0292 | MEDIUM | 4.9 | 0.6% | Jul 8, 2025 | SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote a... |
| CVE-2025-7182 | MEDIUM | 6.1 | 0.3% | Jul 8, 2025 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A... |
| CVE-2025-5463 | MEDIUM | 5.5 | 0.3% | Jul 8, 2025 | Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Se... |
| CVE-2025-5451 | MEDIUM | 4.9 | 0.7% | Jul 8, 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 2... |
| CVE-2025-53545 | MEDIUM | 6.9 | 0.3% | Jul 8, 2025 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-... |
| CVE-2025-53480 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific in... |
| CVE-2025-3630 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug... |
| CVE-2025-2827 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installat... |
| CVE-2025-2793 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 throug... |
| CVE-2025-29267 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to ob... |
| CVE-2025-21433 | MEDIUM | 5.5 | 0.1% | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| CVE-2025-40721 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerab... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now