2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62572HIGH7.8Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2025-62571HIGH7.8Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2025-62569HIGH7Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62565HIGH7.3Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2025-62564HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62563HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62562HIGH7.8Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
CVE-2025-62561HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62560HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62559HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62558HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62557HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62556HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62555HIGH7Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62554HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2025-62553HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62552HIGH7.8Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2025-62550HIGH8.8Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
CVE-2025-62549HIGH8.8Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to exe...
CVE-2025-62474HIGH7.8Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ...
CVE-2025-62472HIGH7.8Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi...
CVE-2025-62470HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2025-62469HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File ...
CVE-2025-62467HIGH7.8Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca...
CVE-2025-62466HIGH7.8Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privilege...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now