2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61845MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61844MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61843MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61842MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory expos...
CVE-2025-61841MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-61840MEDIUM5.5Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ...
CVE-2025-62453MEDIUM5Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to by...
CVE-2025-62449MEDIUM6.8Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extens...
CVE-2025-62214MEDIUM6.7Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize...
CVE-2025-62209MEDIUM5.5Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in...
CVE-2025-62208MEDIUM5.5Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in...
CVE-2025-62206MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize...
CVE-2025-60728MEDIUM4.3Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a n...
CVE-2025-60723MEDIUM6.3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an...
CVE-2025-60722MEDIUM6.5Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori...
CVE-2025-60708MEDIUM6.5Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
CVE-2025-60706MEDIUM5.5Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2025-59513MEDIUM5.5Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca...
CVE-2025-59510MEDIUM5.5Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow...
CVE-2025-59509MEDIUM5.5Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose informatio...
CVE-2025-59240MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to ...
CVE-2025-47179MEDIUM6.7Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-35972MEDIUM6.7Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an ...
CVE-2025-33202MEDIUM6.5NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack over...
CVE-2025-33185MEDIUM5.3NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure.  A succ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now