2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-29955MEDIUM5.5Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
CVE-2025-29954MEDIUM5.9Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacke...
CVE-2025-29839MEDIUM4Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
CVE-2025-29837MEDIUM5.5Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to dis...
CVE-2025-29836MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29835MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29832MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29830MEDIUM6.5Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis...
CVE-2025-29829MEDIUM5.5Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose info...
CVE-2025-27488MEDIUM6.7Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
CVE-2025-26685MEDIUM6.5Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a...
CVE-2025-26684MEDIUM6.7External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil...
CVE-2025-47204MEDIUM6.1An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the sour...
CVE-2025-46721MEDIUM6.1nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 all...
CVE-2025-45867MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the f...
CVE-2025-45866MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the f...
CVE-2025-45864MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the...
CVE-2025-45859MEDIUM5.4TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formM...
CVE-2025-44039MEDIUM5.1CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. ...
CVE-2025-22859MEDIUM5.3A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 th...
CVE-2025-4649MEDIUM4.9Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not co...
CVE-2025-4648MEDIUM5.9The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user w...
CVE-2025-4647MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon we...
CVE-2025-40583MEDIUM6.7A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed...
CVE-2025-40578MEDIUM5.3A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not pro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now