2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49813HIGH7.2An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in ...
CVE-2025-36124HIGH7.5IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security rest...
CVE-2025-53793HIGH7.5Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
CVE-2025-53789HIGH7.8Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate pri...
CVE-2025-53788HIGH7Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevat...
CVE-2025-53784HIGH8.4Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53783HIGH7.5Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
CVE-2025-53779HIGH7.2Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2025-53778HIGH8.8Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-53773HIGH7.8Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio ...
CVE-2025-53772HIGH8.8Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
CVE-2025-53761HIGH7.8Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-53760HIGH7.1Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov...
CVE-2025-53759HIGH7.8Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53741HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53740HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53739HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ...
CVE-2025-53738HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53737HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53735HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53734HIGH7.8Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-53733HIGH8.4Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code loca...
CVE-2025-53732HIGH7.8Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53731HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53730HIGH7.8Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now