2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-50158HIGH7Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose informatio...
CVE-2025-50155HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke...
CVE-2025-50153HIGH7.8Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-49762HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio...
CVE-2025-49761HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-49759HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2025-49758HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2025-49757HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49712HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-49557HIGH8.7Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ...
CVE-2025-49556HIGH7.5Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an...
CVE-2025-49555HIGH8.1Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ...
CVE-2025-49554HIGH7.5Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an...
CVE-2025-47954HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2025-33051HIGH7.5Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker ...
CVE-2025-24999HIGH8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-49564HIGH7.8Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could r...
CVE-2025-49563HIGH7.8Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2025-32086HIGH7.2Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors whe...
CVE-2025-26403HIGH7.2Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) T...
CVE-2025-25273HIGH8.8Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before versio...
CVE-2025-24486HIGH8.8Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 ma...
CVE-2025-24484HIGH8.8Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma...
CVE-2025-24323HIGH7Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before ...
CVE-2025-24305HIGH7.2Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) proc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now