2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30381HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30379HIGH7.8Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locall...
CVE-2025-30378HIGH7Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally...
CVE-2025-30377HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-30376HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30375HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2025-30320MEDIUM5.5InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou...
CVE-2025-30319MEDIUM5.5InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou...
CVE-2025-30318HIGH7.8InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could r...
CVE-2025-30310HIGH7.8Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confu...
CVE-2025-29979HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29978HIGH7.8Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-29977HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29976HIGH7.8Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally...
CVE-2025-29975HIGH7.8Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to ...
CVE-2025-29974MEDIUM5.7Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an...
CVE-2025-29973HIGH7Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
CVE-2025-29971HIGH7.5Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.
CVE-2025-29970HIGH7.8Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-29969HIGH7.5Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code ...
CVE-2025-29968MEDIUM6.5Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service...
CVE-2025-29967HIGH8.8Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a netw...
CVE-2025-29966HIGH8.8Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
CVE-2025-29964HIGH8.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29963HIGH8.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now