2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54917MEDIUM4.3Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a...
CVE-2025-54915MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-54901MEDIUM5.5Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-54252MEDIUM5.4Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability...
CVE-2025-54251MEDIUM4.3Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result ...
CVE-2025-54250MEDIUM4.9Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c...
CVE-2025-54249MEDIUM6.5Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabilit...
CVE-2025-54247MEDIUM6.5Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c...
CVE-2025-54246MEDIUM6.5Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that cou...
CVE-2025-54109MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-54107MEDIUM4.3Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea...
CVE-2025-54104MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-54101MEDIUM4.8Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
CVE-2025-54097MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54096MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54095MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54094MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53810MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53809MEDIUM6.5Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to...
CVE-2025-53808MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53806MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53804MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i...
CVE-2025-53803MEDIUM5.5Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose...
CVE-2025-53799MEDIUM5.5Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information local...
CVE-2025-53798MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now