2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62469HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File ...
CVE-2025-62468MEDIUM5.5Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
CVE-2025-62467HIGH7.8Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca...
CVE-2025-62466HIGH7.8Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privilege...
CVE-2025-62465MEDIUM6.5Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
CVE-2025-62464HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62463MEDIUM6.5Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
CVE-2025-62462HIGH7.8Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-62461HIGH7.8Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca...
CVE-2025-62458HIGH7.8Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-62457HIGH7.8Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally...
CVE-2025-62456HIGH8.8Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a ...
CVE-2025-62455HIGH7.8Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2025-62454HIGH7.8Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges...
CVE-2025-62221HIGH7.8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-61258HIGH7.5Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length valu...
CVE-2025-61078MEDIUM6.1Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrar...
CVE-2025-60024HIGH8.8Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulner...
CVE-2025-59923LOW2.7An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all ...
CVE-2025-59810MEDIUM6.5An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7....
CVE-2025-59808MEDIUM6.8An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, Fort...
CVE-2025-59719CRITICAL9.8An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6...
CVE-2025-59718CRITICAL9.8A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 ...
CVE-2025-59517HIGH7.8Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-59516HIGH7.8Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now