2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26672 | MEDIUM | 6.5 | 1.5% | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-26667 | MEDIUM | 6.5 | 1.5% | Apr 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an... |
| CVE-2025-26664 | MEDIUM | 6.5 | 1.5% | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-26651 | MEDIUM | 6.5 | 2.0% | Apr 8, 2025 | Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny servic... |
| CVE-2025-26644 | MEDIUM | 5.1 | 0.5% | Apr 8, 2025 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hell... |
| CVE-2025-26637 | MEDIUM | 6.8 | 0.8% | Apr 8, 2025 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph... |
| CVE-2025-26635 | MEDIUM | 6.5 | 1.3% | Apr 8, 2025 | Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. |
| CVE-2025-26628 | MEDIUM | 5.5 | 1.2% | Apr 8, 2025 | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locall... |
| CVE-2025-25002 | MEDIUM | 5.7 | 1.0% | Apr 8, 2025 | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose inform... |
| CVE-2025-21203 | MEDIUM | 6.5 | 1.3% | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-21197 | MEDIUM | 6.5 | 2.6% | Apr 8, 2025 | Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder w... |
| CVE-2025-32279 | MEDIUM | 4.3 | 0.2% | Apr 8, 2025 | Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= ... |
| CVE-2025-32211 | MEDIUM | 6.5 | 0.2% | Apr 8, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broads... |
| CVE-2025-32164 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadLis... |
| CVE-2025-30671 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-30670 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ... |
| CVE-2025-27443 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to cond... |
| CVE-2025-27442 | MEDIUM | 5.2 | 0.2% | Apr 8, 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via ad... |
| CVE-2025-27441 | MEDIUM | 5.2 | 0.2% | Apr 8, 2025 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via ad... |
| CVE-2025-27085 | MEDIUM | 4.9 | 0.5% | Apr 8, 2025 | Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conducto... |
| CVE-2025-27084 | MEDIUM | 6.1 | 0.2% | Apr 8, 2025 | A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attac... |
| CVE-2025-32025 | MEDIUM | 6.9 | 0.2% | Apr 8, 2025 | bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The b... |
| CVE-2025-32024 | MEDIUM | 6.9 | 0.2% | Apr 8, 2025 | bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The E... |
| CVE-2025-27079 | MEDIUM | 6 | 0.2% | Apr 8, 2025 | A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an... |
| CVE-2025-27078 | MEDIUM | 6.5 | 0.4% | Apr 8, 2025 | A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now