2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55686HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55685HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55684HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55681HIGH7.8Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-55680HIGH7Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacke...
CVE-2025-55678HIGH7Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2025-55677HIGH7.8Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate priv...
CVE-2025-55340HIGH7Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature lo...
CVE-2025-55339HIGH7.8Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
CVE-2025-55335HIGH7Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-55331HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55328HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an...
CVE-2025-55326HIGH7.5Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net...
CVE-2025-55247HIGH7.3Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileg...
CVE-2025-55240HIGH7.3Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-53782HIGH7.8Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to ele...
CVE-2025-53768HIGH7.8Use after free in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-53717HIGH7Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an aut...
CVE-2025-53150HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-53139HIGH7.1Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security fe...
CVE-2025-50175HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-50174HIGH7Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
CVE-2025-50152HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-48004HIGH7Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47989HIGH7Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now