2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33066 | HIGH | 8.8 | 1.0% | Jun 10, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-33064 | HIGH | 8.8 | 1.1% | Jun 10, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ... |
| CVE-2025-33056 | HIGH | 7.5 | 1.4% | Jun 10, 2025 | Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny se... |
| CVE-2025-33053 | HIGH | 8.8 | 81.6% | Jun 10, 2025 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a ... |
| CVE-2025-33050 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| CVE-2025-32725 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| CVE-2025-32724 | HIGH | 7.5 | 1.5% | Jun 10, 2025 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized a... |
| CVE-2025-32721 | HIGH | 7.3 | 0.6% | Jun 10, 2025 | Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker ... |
| CVE-2025-32718 | HIGH | 7.8 | 0.4% | Jun 10, 2025 | Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. |
| CVE-2025-32716 | HIGH | 7.8 | 0.4% | Jun 10, 2025 | Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. |
| CVE-2025-32714 | HIGH | 7.8 | 1.1% | Jun 10, 2025 | Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. |
| CVE-2025-32713 | HIGH | 7.8 | 0.6% | Jun 10, 2025 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ... |
| CVE-2025-32712 | HIGH | 7.8 | 0.4% | Jun 10, 2025 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
| CVE-2025-32710 | HIGH | 8.1 | 0.9% | Jun 10, 2025 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
| CVE-2025-31104 | HIGH | 7.2 | 1.2% | Jun 10, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2025-30317 | HIGH | 7.8 | 0.3% | Jun 10, 2025 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c... |
| CVE-2025-29828 | HIGH | 8.1 | 1.1% | Jun 10, 2025 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to ... |
| CVE-2025-22256 | HIGH | 8.8 | 0.3% | Jun 10, 2025 | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.... |
| CVE-2025-22254 | HIGH | 7.2 | 0.7% | Jun 10, 2025 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS ... |
| CVE-2025-4678 | HIGH | 7 | 1.5% | Jun 10, 2025 | Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue aff... |
| CVE-2025-4653 | HIGH | 7 | 2.4% | Jun 10, 2025 | Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects ... |
| CVE-2025-49142 | HIGH | 7.1 | 0.3% | Jun 10, 2025 | Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or... |
| CVE-2025-47110 | HIGH | 8.4 | 0.7% | Jun 10, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site... |
| CVE-2025-44044 | HIGH | 7.5 | 0.3% | Jun 10, 2025 | Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable Sea... |
| CVE-2025-43586 | HIGH | 8.1 | 0.5% | Jun 10, 2025 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now