2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7187HIGH8.8A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function ...
CVE-2025-7186HIGH8.8A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unkno...
CVE-2025-53513MEDIUM6.5The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on t...
CVE-2025-53512MEDIUM6.5The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb...
CVE-2025-49760LOW3.5External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a networ...
CVE-2025-49756LOW3.3Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a ...
CVE-2025-49753HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49744HIGH7Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-49742HIGH7.8Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
CVE-2025-49740HIGH8.8Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a ...
CVE-2025-49739HIGH8.8Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to eleva...
CVE-2025-49738HIGH7.8Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to ...
CVE-2025-49737HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an...
CVE-2025-49735HIGH8.1Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-49733HIGH7.8Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2025-49732HIGH7.8Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-49731LOW3.1Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate ...
CVE-2025-49730HIGH7.8Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to el...
CVE-2025-49729HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49727HIGH7Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-49726HIGH7.8Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2025-49725HIGH7.8Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2025-49724HIGH8.8Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a netw...
CVE-2025-49723HIGH8.8Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
CVE-2025-49722MEDIUM5.7Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now