2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-54912HIGH7.8Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
CVE-2025-54911HIGH7.3Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
CVE-2025-54910HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-54908HIGH7.8Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-54907HIGH7.8Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-54906HIGH7.8Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-54905HIGH7.1Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2025-54904HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54903HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54902HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54900HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54899HIGH7.8Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54898HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54897HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-54896HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54895HIGH7.8Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privilege...
CVE-2025-54894HIGH7.8Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2025-54709HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54248HIGH7.7Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c...
CVE-2025-54116HIGH7.3Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
CVE-2025-54115HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an...
CVE-2025-54114HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices...
CVE-2025-54113HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-54112HIGH7Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.
CVE-2025-54111HIGH7.8Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now