2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-53768HIGH7.8Use after free in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-53717HIGH7Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an aut...
CVE-2025-53150HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-53139HIGH7.1Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security fe...
CVE-2025-50175HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-50174HIGH7Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
CVE-2025-50152HIGH7.8Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-48004HIGH7Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47989HIGH7Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-37147HIGH7.1A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root...
CVE-2025-37146HIGH7.2A vulnerability in the web-based management interface of network access point configuration services could allow an auth...
CVE-2025-37134HIGH7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor oper...
CVE-2025-37133HIGH7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor oper...
CVE-2025-37132HIGH7.2An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Contr...
CVE-2025-25004HIGH7.3Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-24990HIGH7.8Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o...
CVE-2025-24052HIGH7.8Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o...
CVE-2025-62172HIGH8.5Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 t...
CVE-2025-57741HIGH7.8An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, ...
CVE-2025-57740HIGH8.8An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, versi...
CVE-2025-57716HIGH7.3An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7....
CVE-2025-46774HIGH7.8An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2...
CVE-2025-31365HIGH7.1An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4....
CVE-2025-25253HIGH7.5An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, ...
CVE-2025-22258HIGH7.2A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now