2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62464 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62462 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62461 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca... |
| CVE-2025-62458 | HIGH | 7.8 | 0.6% | Dec 9, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62457 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally... |
| CVE-2025-62456 | HIGH | 8.8 | 1.0% | Dec 9, 2025 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a ... |
| CVE-2025-62455 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62454 | HIGH | 7.8 | 2.1% | Dec 9, 2025 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges... |
| CVE-2025-62221 | HIGH | 7.8 | 2.3% | Dec 9, 2025 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-61258 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length valu... |
| CVE-2025-60024 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulner... |
| CVE-2025-59517 | HIGH | 7.8 | 2.2% | Dec 9, 2025 | Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59516 | HIGH | 7.8 | 2.1% | Dec 9, 2025 | Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv... |
| CVE-2025-55233 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54100 | HIGH | 7.8 | 1.5% | Dec 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unau... |
| CVE-2025-53949 | HIGH | 8.8 | 15.5% | Dec 9, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-53679 | HIGH | 7.2 | 10.8% | Dec 9, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-46637 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu... |
| CVE-2025-34413 | HIGH | 7.1 | 0.4% | Dec 9, 2025 | Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are... |
| CVE-2025-34396 | HIGH | 7.3 | 0.2% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-33214 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserializatio... |
| CVE-2025-33213 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a d... |
| CVE-2025-56704 | HIGH | 8.8 | 0.7% | Dec 9, 2025 | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validatio... |
| CVE-2025-12946 | HIGH | 7.5 | 0.3% | Dec 9, 2025 | A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can... |
| CVE-2025-12945 | HIGH | 7.2 | 1.6% | Dec 9, 2025 | A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to imp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now