2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55696HIGH7Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized at...
CVE-2025-55694HIGH7.8Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2025-55693HIGH7Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2025-55692HIGH7.8Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2025-55691HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55690HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55689HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55688HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55687HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File Sy...
CVE-2025-55686HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55685HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55684HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55681HIGH7.8Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-55680HIGH7Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacke...
CVE-2025-55678HIGH7Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2025-55677HIGH7.8Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate priv...
CVE-2025-55340HIGH7Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature lo...
CVE-2025-55339HIGH7.8Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
CVE-2025-55335HIGH7Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-55331HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55328HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an...
CVE-2025-55326HIGH7.5Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net...
CVE-2025-55247HIGH7.3Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileg...
CVE-2025-55240HIGH7.3Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-53782HIGH7.8Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to ele...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now