2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26672MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-26667MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an...
CVE-2025-26664MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-26651MEDIUM6.5Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny servic...
CVE-2025-26644MEDIUM5.1Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hell...
CVE-2025-26637MEDIUM6.8Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph...
CVE-2025-26635MEDIUM6.5Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
CVE-2025-26628MEDIUM5.5Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locall...
CVE-2025-25002MEDIUM5.7Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose inform...
CVE-2025-21203MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-21197MEDIUM6.5Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder w...
CVE-2025-32279MEDIUM4.3Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= ...
CVE-2025-32211MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broads...
CVE-2025-32164MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadLis...
CVE-2025-30671MEDIUM6.5Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-30670MEDIUM6.5Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-27443MEDIUM5.5Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to cond...
CVE-2025-27442MEDIUM5.2Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via ad...
CVE-2025-27441MEDIUM5.2Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via ad...
CVE-2025-27085MEDIUM4.9Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conducto...
CVE-2025-27084MEDIUM6.1A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attac...
CVE-2025-32025MEDIUM6.9bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The b...
CVE-2025-32024MEDIUM6.9bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The E...
CVE-2025-27079MEDIUM6A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an...
CVE-2025-27078MEDIUM6.5A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now