2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49721HIGH7.8Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49719HIGH7.5Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2025-49718HIGH7.5Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2025-49717HIGH8.5Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2025-49716HIGH7.5Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
CVE-2025-49714HIGH7.8Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locall...
CVE-2025-49711HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-49706MEDIUM6.5Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ...
CVE-2025-49705HIGH7.8Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-49704HIGH8.8Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t...
CVE-2025-49703HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49702HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2025-49701HIGH8.8Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-49700HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49699HIGH7Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-49698HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49697HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-49696HIGH8.4Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-49695HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-49694HIGH7.8Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49693HIGH7.8Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49691HIGH8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
CVE-2025-49690HIGH7.4Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem...
CVE-2025-49689HIGH7.8Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally...
CVE-2025-49688HIGH8.8Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a n...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now