2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-33066HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-33064HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ...
CVE-2025-33056HIGH7.5Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny se...
CVE-2025-33053HIGH8.8External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a ...
CVE-2025-33050HIGH7.5Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-32725HIGH7.5Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-32724HIGH7.5Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized a...
CVE-2025-32721HIGH7.3Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker ...
CVE-2025-32718HIGH7.8Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.
CVE-2025-32716HIGH7.8Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
CVE-2025-32714HIGH7.8Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2025-32713HIGH7.8Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges ...
CVE-2025-32712HIGH7.8Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-32710HIGH8.1Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2025-31104HIGH7.2An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2025-30317HIGH7.8InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c...
CVE-2025-29828HIGH8.1Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to ...
CVE-2025-22256HIGH8.8A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1....
CVE-2025-22254HIGH7.2An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS ...
CVE-2025-4678HIGH7Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue aff...
CVE-2025-4653HIGH7Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects ...
CVE-2025-49142HIGH7.1Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or...
CVE-2025-47110HIGH8.4Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site...
CVE-2025-44044HIGH7.5Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable Sea...
CVE-2025-43586HIGH8.1Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now