2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62464HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62462HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62461HIGH7.8Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca...
CVE-2025-62458HIGH7.8Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-62457HIGH7.8Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally...
CVE-2025-62456HIGH8.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a ...
CVE-2025-62455HIGH7.8Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2025-62454HIGH7.8Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges...
CVE-2025-62221HIGH7.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-61258HIGH7.5Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length valu...
CVE-2025-60024HIGH8.8Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulner...
CVE-2025-59517HIGH7.8Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-59516HIGH7.8Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv...
CVE-2025-55233HIGH7.8Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-54100HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unau...
CVE-2025-53949HIGH8.8An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-53679HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-46637HIGH7.3Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu...
CVE-2025-34413HIGH7.1Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are...
CVE-2025-34396HIGH7.3MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-33214HIGH8.8NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserializatio...
CVE-2025-33213HIGH8.8NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a d...
CVE-2025-56704HIGH8.8LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validatio...
CVE-2025-12946HIGH7.5A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can...
CVE-2025-12945HIGH7.2A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to imp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now