2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33075HIGH7.8Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele...
CVE-2025-33073HIGH8.8Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2025-33071HIGH8.1Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-33070HIGH8.1Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-33069MEDIUM5.1Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to b...
CVE-2025-33068HIGH7.5Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ...
CVE-2025-33067HIGH8.4Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2025-33066HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-33065MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33064HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ...
CVE-2025-33063MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33062MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33061MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33060MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33059MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33058MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33057MEDIUM6.5Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a ...
CVE-2025-33056HIGH7.5Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny se...
CVE-2025-33055MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33053HIGH8.8External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a ...
CVE-2025-33052MEDIUM5.5Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2025-33050HIGH7.5Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-32725HIGH7.5Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-32724HIGH7.5Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized a...
CVE-2025-32722MEDIUM5.5Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now