2025 CVE Vulnerabilities

45,345 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49738HIGH7.8Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to ...
CVE-2025-49737HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an...
CVE-2025-49735HIGH8.1Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-49733HIGH7.8Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2025-49732HIGH7.8Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-49730HIGH7.8Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to el...
CVE-2025-49729HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49727HIGH7Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-49726HIGH7.8Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2025-49725HIGH7.8Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2025-49724HIGH8.8Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a netw...
CVE-2025-49723HIGH8.8Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
CVE-2025-49721HIGH7.8Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49719HIGH7.5Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2025-49718HIGH7.5Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2025-49717HIGH8.5Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2025-49716HIGH7.5Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
CVE-2025-49714HIGH7.8Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locall...
CVE-2025-49711HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-49705HIGH7.8Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-49704HIGH8.8Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t...
CVE-2025-49703HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-49702HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2025-49701HIGH8.8Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-49700HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now