2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49755 | MEDIUM | 4.3 | 0.4% | Aug 12, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac... |
| CVE-2025-49751 | MEDIUM | 6.8 | 0.4% | Aug 12, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. |
| CVE-2025-49745 | MEDIUM | 5.4 | 0.5% | Aug 12, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premi... |
| CVE-2025-49743 | MEDIUM | 6.7 | 0.4% | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon... |
| CVE-2025-49736 | MEDIUM | 4.3 | 0.5% | Aug 12, 2025 | The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over ... |
| CVE-2025-49712 | HIGH | 8.8 | 17.2% | Aug 12, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2025-49707 | MEDIUM | 5.5 | 0.4% | Aug 12, 2025 | Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. |
| CVE-2025-49559 | MEDIUM | 5.3 | 0.6% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an... |
| CVE-2025-49558 | MEDIUM | 5.9 | 0.4% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ... |
| CVE-2025-49557 | HIGH | 8.7 | 0.6% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ... |
| CVE-2025-49556 | HIGH | 7.5 | 0.6% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an... |
| CVE-2025-49555 | HIGH | 8.1 | 0.9% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ... |
| CVE-2025-49554 | HIGH | 7.5 | 0.5% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an... |
| CVE-2025-48807 | MEDIUM | 6.7 | 0.4% | Aug 12, 2025 | Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to ... |
| CVE-2025-47954 | HIGH | 8.8 | 1.4% | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-33051 | HIGH | 7.5 | 1.1% | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker ... |
| CVE-2025-25007 | MEDIUM | 5.3 | 0.8% | Aug 12, 2025 | Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to pe... |
| CVE-2025-25006 | MEDIUM | 5.3 | 0.8% | Aug 12, 2025 | Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform ... |
| CVE-2025-25005 | MEDIUM | 6.5 | 1.3% | Aug 12, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network... |
| CVE-2025-24999 | HIGH | 8.8 | 1.5% | Aug 12, 2025 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-20044 | MEDIUM | 5.6 | 0.1% | Aug 12, 2025 | Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially ... |
| CVE-2025-55167 | CRITICAL | 9.8 | 0.5% | Aug 12, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio... |
| CVE-2025-55166 | MEDIUM | 5.1 | 0.4% | Aug 12, 2025 | savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method... |
| CVE-2025-49568 | MEDIUM | 5.5 | 0.2% | Aug 12, 2025 | Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclo... |
| CVE-2025-49567 | MEDIUM | 5.5 | 0.2% | Aug 12, 2025 | Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now