2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59255HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-59254HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-59250HIGH8.1Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a netwo...
CVE-2025-59249HIGH8.8Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-59248HIGH7.5Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a networ...
CVE-2025-59243HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59242HIGH7.8Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri...
CVE-2025-59241HIGH7.8Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allow...
CVE-2025-59238HIGH7.8Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-59237HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-59236HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59235HIGH7.1Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-59234HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-59233HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2025-59232HIGH7.1Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-59231HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2025-59230HIGH7.8Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ...
CVE-2025-59228HIGH8.8Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-59227HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-59226HIGH7.8Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-59225HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59224HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59223HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59222HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-59221HIGH7Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now