2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62549 | HIGH | 8.8 | 1.2% | Dec 9, 2025 | Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to exe... |
| CVE-2025-62474 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ... |
| CVE-2025-62473 | MEDIUM | 6.5 | 1.0% | Dec 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-62472 | HIGH | 7.8 | 2.0% | Dec 9, 2025 | Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi... |
| CVE-2025-62470 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ... |
| CVE-2025-62469 | HIGH | 7 | 0.2% | Dec 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File ... |
| CVE-2025-62468 | MEDIUM | 5.5 | 0.5% | Dec 9, 2025 | Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
| CVE-2025-62467 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca... |
| CVE-2025-62466 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privilege... |
| CVE-2025-62465 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. |
| CVE-2025-62464 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62463 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. |
| CVE-2025-62462 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62461 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca... |
| CVE-2025-62458 | HIGH | 7.8 | 0.6% | Dec 9, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62457 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally... |
| CVE-2025-62456 | HIGH | 8.8 | 1.0% | Dec 9, 2025 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a ... |
| CVE-2025-62455 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62454 | HIGH | 7.8 | 2.1% | Dec 9, 2025 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges... |
| CVE-2025-62221 | HIGH | 7.8 | 2.3% | Dec 9, 2025 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-61258 | HIGH | 7.5 | 0.5% | Dec 9, 2025 | Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length valu... |
| CVE-2025-61078 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrar... |
| CVE-2025-60024 | HIGH | 8.8 | 0.4% | Dec 9, 2025 | Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulner... |
| CVE-2025-59923 | LOW | 2.7 | 0.2% | Dec 9, 2025 | An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ... |
| CVE-2025-59810 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now