2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49730 | HIGH | 7.8 | 0.6% | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to el... |
| CVE-2025-49729 | HIGH | 8.8 | 0.6% | Jul 8, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-49727 | HIGH | 7 | 0.3% | Jul 8, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49726 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49725 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49724 | HIGH | 8.8 | 6.9% | Jul 8, 2025 | Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a netw... |
| CVE-2025-49723 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. |
| CVE-2025-49721 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-49719 | HIGH | 7.5 | 10.2% | Jul 8, 2025 | Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-49718 | HIGH | 7.5 | 2.8% | Jul 8, 2025 | Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-49717 | HIGH | 8.5 | 0.9% | Jul 8, 2025 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2025-49716 | HIGH | 7.5 | 1.3% | Jul 8, 2025 | Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. |
| CVE-2025-49714 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locall... |
| CVE-2025-49711 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-49705 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-49704 | HIGH | 8.8 | 99.9% | Jul 8, 2025 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t... |
| CVE-2025-49703 | HIGH | 7.8 | 0.6% | Jul 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-49702 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe... |
| CVE-2025-49701 | HIGH | 8.8 | 0.8% | Jul 8, 2025 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-49700 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-49699 | HIGH | 7 | 0.3% | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-49698 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-49697 | HIGH | 8.4 | 0.5% | Jul 8, 2025 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-49696 | HIGH | 8.4 | 0.6% | Jul 8, 2025 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-49695 | HIGH | 8.4 | 0.6% | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now