2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47175HIGH7.8Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-47174HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-47173HIGH7.8Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47172HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo...
CVE-2025-47170HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47169HIGH7.8Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47168HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47167HIGH8.4Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2025-47166HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-47165HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-47164HIGH8.4Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47163HIGH8.8Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-47162HIGH8.4Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47108HIGH7.8Substance3D - Painter versions 11.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result...
CVE-2025-43593HIGH7.8InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could r...
CVE-2025-43590HIGH7.8InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could r...
CVE-2025-43589HIGH7.8InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could result ...
CVE-2025-43558HIGH7.8InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could r...
CVE-2025-33112HIGH8.4IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to...
CVE-2025-33075HIGH7.8Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele...
CVE-2025-33073HIGH8.8Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2025-33071HIGH8.1Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-33070HIGH8.1Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-33068HIGH7.5Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ...
CVE-2025-33067HIGH8.4Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now