2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50158 | HIGH | 7 | 0.4% | Aug 12, 2025 | Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose informatio... |
| CVE-2025-50155 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke... |
| CVE-2025-50153 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49762 | HIGH | 7 | 0.3% | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio... |
| CVE-2025-49761 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49759 | HIGH | 8.8 | 1.0% | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-49758 | HIGH | 8.8 | 0.9% | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-49757 | HIGH | 8.8 | 0.9% | Aug 12, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-49712 | HIGH | 8.8 | 17.2% | Aug 12, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2025-49557 | HIGH | 8.7 | 0.6% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ... |
| CVE-2025-49556 | HIGH | 7.5 | 0.6% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an... |
| CVE-2025-49555 | HIGH | 8.1 | 0.9% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a ... |
| CVE-2025-49554 | HIGH | 7.5 | 0.5% | Aug 12, 2025 | Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an... |
| CVE-2025-47954 | HIGH | 8.8 | 1.4% | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-33051 | HIGH | 7.5 | 1.1% | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker ... |
| CVE-2025-24999 | HIGH | 8.8 | 1.5% | Aug 12, 2025 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-49564 | HIGH | 7.8 | 0.3% | Aug 12, 2025 | Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could r... |
| CVE-2025-49563 | HIGH | 7.8 | 0.2% | Aug 12, 2025 | Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2025-32086 | HIGH | 7.2 | 0.1% | Aug 12, 2025 | Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors whe... |
| CVE-2025-26403 | HIGH | 7.2 | 0.1% | Aug 12, 2025 | Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) T... |
| CVE-2025-25273 | HIGH | 8.8 | 0.1% | Aug 12, 2025 | Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before versio... |
| CVE-2025-24486 | HIGH | 8.8 | 0.1% | Aug 12, 2025 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 ma... |
| CVE-2025-24484 | HIGH | 8.8 | 0.1% | Aug 12, 2025 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma... |
| CVE-2025-24323 | HIGH | 7 | 0.1% | Aug 12, 2025 | Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before ... |
| CVE-2025-24305 | HIGH | 7.2 | 0.1% | Aug 12, 2025 | Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) proc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now