2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64153HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7...
CVE-2025-64086HIGH7.5A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allo...
CVE-2025-64085HIGH7.5A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows att...
CVE-2025-62631MEDIUM5.6An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all vers...
CVE-2025-62573HIGH7Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2025-62572HIGH7.8Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2025-62571HIGH7.8Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2025-62570MEDIUM5.5Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information loc...
CVE-2025-62569HIGH7Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62567MEDIUM5.3Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
CVE-2025-62565HIGH7.3Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2025-62564HIGH7.8Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62563HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62562HIGH7.8Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
CVE-2025-62561HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62560HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62559HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62558HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62557HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62556HIGH7.8Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62555HIGH7Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62554HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2025-62553HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62552HIGH7.8Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2025-62550HIGH8.8Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now