2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-29962HIGH8.8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29961MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29960MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29959MEDIUM6.5Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis...
CVE-2025-29958MEDIUM6.5Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis...
CVE-2025-29957MEDIUM6.2Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally...
CVE-2025-29956MEDIUM5.4Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
CVE-2025-29955MEDIUM5.5Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
CVE-2025-29954MEDIUM5.9Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacke...
CVE-2025-29842HIGH7.5Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security...
CVE-2025-29841HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Managemen...
CVE-2025-29840HIGH8.8Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29839MEDIUM4Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
CVE-2025-29838HIGH7Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.
CVE-2025-29837MEDIUM5.5Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to dis...
CVE-2025-29836MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29835MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29833HIGH7.7Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to exec...
CVE-2025-29832MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-29831HIGH7.5Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-29830MEDIUM6.5Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis...
CVE-2025-29829MEDIUM5.5Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose info...
CVE-2025-29826HIGH8.8Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elev...
CVE-2025-27488MEDIUM6.7Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
CVE-2025-27468HIGH7Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now