2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61845 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61844 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61843 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61842 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory expos... |
| CVE-2025-61841 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61840 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-62453 | MEDIUM | 5 | 0.4% | Nov 11, 2025 | Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to by... |
| CVE-2025-62449 | MEDIUM | 6.8 | 0.4% | Nov 11, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extens... |
| CVE-2025-62214 | MEDIUM | 6.7 | 1.0% | Nov 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize... |
| CVE-2025-62209 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in... |
| CVE-2025-62208 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in... |
| CVE-2025-62206 | MEDIUM | 6.5 | 0.9% | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize... |
| CVE-2025-60728 | MEDIUM | 4.3 | 0.7% | Nov 11, 2025 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a n... |
| CVE-2025-60723 | MEDIUM | 6.3 | 0.8% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an... |
| CVE-2025-60722 | MEDIUM | 6.5 | 0.8% | Nov 11, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori... |
| CVE-2025-60708 | MEDIUM | 6.5 | 0.4% | Nov 11, 2025 | Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. |
| CVE-2025-60706 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. |
| CVE-2025-59513 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca... |
| CVE-2025-59510 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow... |
| CVE-2025-59509 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose informatio... |
| CVE-2025-59240 | MEDIUM | 5.5 | 0.6% | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to ... |
| CVE-2025-47179 | MEDIUM | 6.7 | 0.3% | Nov 11, 2025 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2025-35972 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an ... |
| CVE-2025-33202 | MEDIUM | 6.5 | 0.4% | Nov 11, 2025 | NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack over... |
| CVE-2025-33185 | MEDIUM | 5.3 | 0.7% | Nov 11, 2025 | NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure. A succ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now