2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50174HIGH7Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
CVE-2025-50152HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-49708CRITICAL9.9Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
CVE-2025-48813MEDIUM4.7Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
CVE-2025-48004HIGH7Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47989HIGH7Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-47979MEDIUM5.5Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i...
CVE-2025-37148MEDIUM6.5A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta...
CVE-2025-37147HIGH7.1A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root...
CVE-2025-37146HIGH7.2A vulnerability in the web-based management interface of network access point configuration services could allow an auth...
CVE-2025-37145MEDIUM4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit...
CVE-2025-37144MEDIUM4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit...
CVE-2025-37143MEDIUM4.9An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/...
CVE-2025-37142MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37141MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37140MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37139MEDIUM6A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i...
CVE-2025-37138MEDIUM6.2An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Cont...
CVE-2025-37137MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37136MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37135MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37134HIGH7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor oper...
CVE-2025-37133HIGH7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor oper...
CVE-2025-37132HIGH7.2An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Contr...
CVE-2025-36730MEDIUM4.6A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now