2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33075 | HIGH | 7.8 | 0.5% | Jun 10, 2025 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele... |
| CVE-2025-33073 | HIGH | 8.8 | 64.3% | Jun 10, 2025 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-33071 | HIGH | 8.1 | 13.5% | Jun 10, 2025 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-33070 | HIGH | 8.1 | 6.1% | Jun 10, 2025 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-33069 | MEDIUM | 5.1 | 0.3% | Jun 10, 2025 | Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to b... |
| CVE-2025-33068 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ... |
| CVE-2025-33067 | HIGH | 8.4 | 0.4% | Jun 10, 2025 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-33066 | HIGH | 8.8 | 1.0% | Jun 10, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-33065 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33064 | HIGH | 8.8 | 1.1% | Jun 10, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ... |
| CVE-2025-33063 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33062 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33061 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33060 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33059 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33058 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33057 | MEDIUM | 6.5 | 1.4% | Jun 10, 2025 | Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a ... |
| CVE-2025-33056 | HIGH | 7.5 | 1.4% | Jun 10, 2025 | Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny se... |
| CVE-2025-33055 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-33053 | HIGH | 8.8 | 81.6% | Jun 10, 2025 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a ... |
| CVE-2025-33052 | MEDIUM | 5.5 | 0.5% | Jun 10, 2025 | Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
| CVE-2025-33050 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| CVE-2025-32725 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| CVE-2025-32724 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized a... |
| CVE-2025-32722 | MEDIUM | 5.5 | 1.0% | Jun 10, 2025 | Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now