2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55686 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55685 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55684 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55681 | HIGH | 7.8 | 5.1% | Oct 14, 2025 | Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55680 | HIGH | 7 | 0.4% | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacke... |
| CVE-2025-55678 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55677 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate priv... |
| CVE-2025-55340 | HIGH | 7 | 0.3% | Oct 14, 2025 | Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature lo... |
| CVE-2025-55339 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55335 | HIGH | 7 | 0.2% | Oct 14, 2025 | Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-55331 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55328 | HIGH | 7 | 0.2% | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an... |
| CVE-2025-55326 | HIGH | 7.5 | 0.8% | Oct 14, 2025 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net... |
| CVE-2025-55247 | HIGH | 7.3 | 0.6% | Oct 14, 2025 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileg... |
| CVE-2025-55240 | HIGH | 7.3 | 0.3% | Oct 14, 2025 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53782 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to ele... |
| CVE-2025-53768 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Xbox allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53717 | HIGH | 7 | 0.3% | Oct 14, 2025 | Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an aut... |
| CVE-2025-53150 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53139 | HIGH | 7.1 | 0.3% | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security fe... |
| CVE-2025-50175 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
| CVE-2025-50174 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-50152 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-48004 | HIGH | 7 | 1.8% | Oct 14, 2025 | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47989 | HIGH | 7 | 0.5% | Oct 14, 2025 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now