2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-58731HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58730HIGH7Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-58728HIGH7.8Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-58727HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices...
CVE-2025-58726HIGH7.5Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-58725HIGH7Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
CVE-2025-58724HIGH7.8Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-58722HIGH7.8Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-58720HIGH7.8Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized atta...
CVE-2025-58718HIGH8.8Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-58716HIGH8.8Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
CVE-2025-58715HIGH8.8Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
CVE-2025-58714HIGH7.8Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privil...
CVE-2025-55701HIGH7.8Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges ...
CVE-2025-55698HIGH7.7Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.
CVE-2025-55697HIGH7.8Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.
CVE-2025-55696HIGH7Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized at...
CVE-2025-55694HIGH7.8Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2025-55693HIGH7Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2025-55692HIGH7.8Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2025-55691HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55690HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55689HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55688HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55687HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File Sy...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now