2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49755MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac...
CVE-2025-49751MEDIUM6.8Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2025-49745MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premi...
CVE-2025-49743MEDIUM6.7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-49736MEDIUM4.3The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over ...
CVE-2025-49712HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-49707MEDIUM5.5Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
CVE-2025-49559MEDIUM5.3Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an...
CVE-2025-49558MEDIUM5.9Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ...
CVE-2025-49557HIGH8.7Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ...
CVE-2025-49556HIGH7.5Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an...
CVE-2025-49555HIGH8.1Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ...
CVE-2025-49554HIGH7.5Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an...
CVE-2025-48807MEDIUM6.7Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to ...
CVE-2025-47954HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2025-33051HIGH7.5Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker ...
CVE-2025-25007MEDIUM5.3Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to pe...
CVE-2025-25006MEDIUM5.3Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform ...
CVE-2025-25005MEDIUM6.5Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network...
CVE-2025-24999HIGH8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-20044MEDIUM5.6Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially ...
CVE-2025-55167CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio...
CVE-2025-55166MEDIUM5.1savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method...
CVE-2025-49568MEDIUM5.5Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclo...
CVE-2025-49567MEDIUM5.5Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now