2025 CVE Vulnerabilities
45,346 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47994 | HIGH | 8.6 | 2.8% | Jul 8, 2025 | Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47993 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47991 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47988 | HIGH | 7.5 | 0.8% | Jul 8, 2025 | Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to exec... |
| CVE-2025-47987 | HIGH | 7.8 | 1.7% | Jul 8, 2025 | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges local... |
| CVE-2025-47986 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47985 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47984 | HIGH | 7.5 | 14.3% | Jul 8, 2025 | Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-47982 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47976 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47975 | HIGH | 7 | 0.3% | Jul 8, 2025 | Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47973 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47972 | HIGH | 8 | 0.5% | Jul 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed... |
| CVE-2025-47971 | HIGH | 7.8 | 0.5% | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47178 | HIGH | 8 | 2.0% | Jul 8, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ... |
| CVE-2025-47159 | HIGH | 7.8 | 0.4% | Jul 8, 2025 | Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele... |
| CVE-2025-33054 | HIGH | 8.1 | 0.8% | Jul 8, 2025 | Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo... |
| CVE-2025-21166 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-21165 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-21164 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-6771 | HIGH | 7.2 | 14.8% | Jul 8, 2025 | OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re... |
| CVE-2025-43019 | HIGH | 7.8 | 0.1% | Jul 8, 2025 | A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc... |
| CVE-2025-3648 | HIGH | 8.2 | 1.7% | Jul 8, 2025 | A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. ... |
| CVE-2025-7326 | HIGH | 7 | 0.6% | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi... |
| CVE-2025-7037 | HIGH | 7.2 | 0.9% | Jul 8, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now