2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59514 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally... |
| CVE-2025-59512 | HIGH | 7.8 | 2.8% | Nov 11, 2025 | Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privi... |
| CVE-2025-59511 | HIGH | 7.8 | 0.4% | Nov 11, 2025 | External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locall... |
| CVE-2025-59508 | HIGH | 7 | 0.2% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an ... |
| CVE-2025-59507 | HIGH | 7 | 0.2% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an ... |
| CVE-2025-59506 | HIGH | 7 | 0.2% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an... |
| CVE-2025-59505 | HIGH | 7.8 | 0.4% | Nov 11, 2025 | Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59504 | HIGH | 7.3 | 0.3% | Nov 11, 2025 | Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. |
| CVE-2025-59499 | HIGH | 8.8 | 1.1% | Nov 11, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-30398 | HIGH | 8.1 | 0.8% | Nov 11, 2025 | Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-61832 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2025-61824 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2025-61818 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c... |
| CVE-2025-61817 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c... |
| CVE-2025-61816 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in... |
| CVE-2025-61815 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in a... |
| CVE-2025-61814 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in a... |
| CVE-2025-35971 | HIGH | 8.3 | 0.2% | Nov 11, 2025 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev... |
| CVE-2025-35968 | HIGH | 7.1 | 0.1% | Nov 11, 2025 | Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of pri... |
| CVE-2025-35967 | HIGH | 7.4 | 0.2% | Nov 11, 2025 | Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Devi... |
| CVE-2025-35963 | HIGH | 8.3 | 0.2% | Nov 11, 2025 | Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 w... |
| CVE-2025-33186 | HIGH | 8.8 | 0.3% | Nov 11, 2025 | NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of... |
| CVE-2025-33178 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data cre... |
| CVE-2025-33029 | HIGH | 8.3 | 0.2% | Nov 11, 2025 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev... |
| CVE-2025-33000 | HIGH | 8.8 | 0.1% | Nov 11, 2025 | Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications ma... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now