2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-49694HIGH7.8Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49693HIGH7.8Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49691HIGH8Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
CVE-2025-49690HIGH7.4Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem...
CVE-2025-49689HIGH7.8Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally...
CVE-2025-49688HIGH8.8Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a n...
CVE-2025-49687HIGH8.8Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-49686HIGH7.8Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2025-49685HIGH7Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2025-49683HIGH7.8Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
CVE-2025-49682HIGH7.3Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2025-49680HIGH7.3Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized atta...
CVE-2025-49679HIGH7.8Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2025-49678HIGH7Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2025-49677HIGH7Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49676HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49675HIGH7.8Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-49674HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49673HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49672HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49669HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49668HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-49667HIGH7.8Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
CVE-2025-49666HIGH7.2Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
CVE-2025-49665HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now