2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47175 | HIGH | 7.8 | 2.1% | Jun 10, 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-47174 | HIGH | 7.8 | 0.5% | Jun 10, 2025 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-47173 | HIGH | 7.8 | 0.5% | Jun 10, 2025 | Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47172 | HIGH | 8.8 | 1.5% | Jun 10, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo... |
| CVE-2025-47170 | HIGH | 7.8 | 0.6% | Jun 10, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-47169 | HIGH | 7.8 | 0.6% | Jun 10, 2025 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-47168 | HIGH | 7.8 | 0.5% | Jun 10, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-47167 | HIGH | 8.4 | 0.6% | Jun 10, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe... |
| CVE-2025-47166 | HIGH | 8.8 | 12.3% | Jun 10, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2025-47165 | HIGH | 7.8 | 1.8% | Jun 10, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-47164 | HIGH | 8.4 | 0.6% | Jun 10, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47163 | HIGH | 8.8 | 10.7% | Jun 10, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2025-47162 | HIGH | 8.4 | 0.7% | Jun 10, 2025 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47108 | HIGH | 7.8 | 0.2% | Jun 10, 2025 | Substance3D - Painter versions 11.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result... |
| CVE-2025-43593 | HIGH | 7.8 | 0.2% | Jun 10, 2025 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could r... |
| CVE-2025-43590 | HIGH | 7.8 | 0.2% | Jun 10, 2025 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could r... |
| CVE-2025-43589 | HIGH | 7.8 | 0.3% | Jun 10, 2025 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could result ... |
| CVE-2025-43558 | HIGH | 7.8 | 0.2% | Jun 10, 2025 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could r... |
| CVE-2025-33112 | HIGH | 8.4 | 0.2% | Jun 10, 2025 | IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to... |
| CVE-2025-33075 | HIGH | 7.8 | 0.5% | Jun 10, 2025 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele... |
| CVE-2025-33073 | HIGH | 8.8 | 64.3% | Jun 10, 2025 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-33071 | HIGH | 8.1 | 13.5% | Jun 10, 2025 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-33070 | HIGH | 8.1 | 6.1% | Jun 10, 2025 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-33068 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ... |
| CVE-2025-33067 | HIGH | 8.4 | 0.4% | Jun 10, 2025 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now