2025 CVE Vulnerabilities

45,346 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47994HIGH8.6Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47993HIGH7.8Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-47991HIGH7.8Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-47988HIGH7.5Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to exec...
CVE-2025-47987HIGH7.8Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges local...
CVE-2025-47986HIGH8.8Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47985HIGH7.8Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
CVE-2025-47984HIGH7.5Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
CVE-2025-47982HIGH7.8Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-47976HIGH7.8Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47975HIGH7Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47973HIGH7.8Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47972HIGH8Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed...
CVE-2025-47971HIGH7.8Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47178HIGH8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ...
CVE-2025-47159HIGH7.8Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele...
CVE-2025-33054HIGH8.1Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo...
CVE-2025-21166HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-21165HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-21164HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-6771HIGH7.2OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re...
CVE-2025-43019HIGH7.8A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc...
CVE-2025-3648HIGH8.2A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. ...
CVE-2025-7326HIGH7Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi...
CVE-2025-7037HIGH7.2SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now