2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32721HIGH7.3Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker ...
CVE-2025-32720MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-32719MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-32718HIGH7.8Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.
CVE-2025-32716HIGH7.8Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2025-32715MEDIUM6.5Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2025-32714HIGH7.8Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2025-32713HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2025-32712HIGH7.8Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-32710HIGH8.1Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2025-31104HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2025-30321MEDIUM5.5InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that cou...
CVE-2025-30317HIGH7.8InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2025-29828HIGH8.1Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to ...
CVE-2025-25250MEDIUM4.3An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS ...
CVE-2025-24471MEDIUM6.5An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below m...
CVE-2025-24069MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-24068MEDIUM5.5Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-24065MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-22256HIGH8.8A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1....
CVE-2025-22254HIGH7.2An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS ...
CVE-2025-22251MEDIUM5.3An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 t...
CVE-2025-4801Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-4678HIGH7Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue aff...
CVE-2025-4653HIGH7Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now