2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30324HIGH7.8Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi...
CVE-2025-30322HIGH7.8Substance3D - Painter versions 11.0 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2025-27197HIGH7.8Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arb...
CVE-2025-4658CRITICAL9.8Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by...
CVE-2025-47280MEDIUM6.1Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch a...
CVE-2025-3757CRITICAL9.8Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by...
CVE-2025-32709HIGH7.8Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi...
CVE-2025-32707HIGH7.8Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-32706HIGH7.8Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges l...
CVE-2025-32705HIGH7.8Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
CVE-2025-32704HIGH7.8Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-32703MEDIUM5.5Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locall...
CVE-2025-32702HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthori...
CVE-2025-32701HIGH7.8Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-30400HIGH7.8Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-30397HIGH7.5Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attac...
CVE-2025-30394MEDIUM5.9Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to ...
CVE-2025-30393HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30388HIGH7.8Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2025-30387CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker ...
CVE-2025-30386HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-30385HIGH7.8Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-30384HIGH7Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally...
CVE-2025-30383HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2025-30382HIGH7.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now