2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20613LOW3.3Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may allow an authenticat...
CVE-2025-20109HIGH7.8Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authe...
CVE-2025-20099MEDIUM6.7Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user...
CVE-2025-20093HIGH8.6Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethern...
CVE-2025-20092MEDIUM6.7Uncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to pot...
CVE-2025-20090MEDIUM6.8Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authen...
CVE-2025-20087MEDIUM6.7Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated...
CVE-2025-20077MEDIUM5.6Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) referenc...
CVE-2025-20074HIGH7.8Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before ver...
CVE-2025-20067MEDIUM6.8Observable timing discrepancy in firmware for some Intel(R) CSME and Intel(R) SPS may allow a privileged user to potenti...
CVE-2025-20053HIGH7.2Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user t...
CVE-2025-20048MEDIUM6.7Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated u...
CVE-2025-20037HIGH7.2Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allo...
CVE-2025-20025MEDIUM4.4Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticate...
CVE-2025-20023MEDIUM6.7Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to p...
CVE-2025-20017MEDIUM6.7Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated u...
CVE-2025-8452MEDIUM4.3By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-fu...
CVE-2025-55164HIGH8.8content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in ...
CVE-2025-55011MEDIUM5.3Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskF...
CVE-2025-55010HIGH7.2Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deser...
CVE-2025-54864HIGH7.5Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/pus...
CVE-2025-54800MEDIUM6.1Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can intro...
CVE-2025-3089MEDIUM5.3ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This v...
CVE-2025-38500HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing ...
CVE-2025-8310HIGH8.8Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now