2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-59213HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ...
CVE-2025-59210HIGH7.4Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59208HIGH7.1Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
CVE-2025-59207HIGH7.8Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-59206HIGH7.4Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59205HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-59202HIGH7Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2025-59201HIGH7.8Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privilege...
CVE-2025-59200HIGH7.7Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Clie...
CVE-2025-59199HIGH7.8Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locall...
CVE-2025-59196HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allo...
CVE-2025-59195HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-59194HIGH7Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-59193HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic...
CVE-2025-59192HIGH7.8Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-59191HIGH7.8Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privi...
CVE-2025-59189HIGH7Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2025-59187HIGH7.8Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-58738HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58737HIGH7Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.
CVE-2025-58736HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58735HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58734HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58733HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58732HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now