2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62549HIGH8.8Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to exe...
CVE-2025-62474HIGH7.8Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ...
CVE-2025-62473MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-62472HIGH7.8Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi...
CVE-2025-62470HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2025-62469HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File ...
CVE-2025-62468MEDIUM5.5Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
CVE-2025-62467HIGH7.8Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca...
CVE-2025-62466HIGH7.8Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privilege...
CVE-2025-62465MEDIUM6.5Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
CVE-2025-62464HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62463MEDIUM6.5Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
CVE-2025-62462HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62461HIGH7.8Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca...
CVE-2025-62458HIGH7.8Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-62457HIGH7.8Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally...
CVE-2025-62456HIGH8.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a ...
CVE-2025-62455HIGH7.8Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2025-62454HIGH7.8Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges...
CVE-2025-62221HIGH7.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-61258HIGH7.5Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length valu...
CVE-2025-61078MEDIUM6.1Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrar...
CVE-2025-60024HIGH8.8Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulner...
CVE-2025-59923LOW2.7An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ...
CVE-2025-59810MEDIUM6.5An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now