2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60707 | HIGH | 7.8 | 0.5% | Nov 11, 2025 | Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally... |
| CVE-2025-60706 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. |
| CVE-2025-60705 | HIGH | 7.8 | 2.3% | Nov 11, 2025 | Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges... |
| CVE-2025-60704 | HIGH | 7.5 | 0.5% | Nov 11, 2025 | Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-60703 | HIGH | 7.8 | 0.4% | Nov 11, 2025 | Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59515 | HIGH | 7 | 0.3% | Nov 11, 2025 | Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59514 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally... |
| CVE-2025-59513 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca... |
| CVE-2025-59512 | HIGH | 7.8 | 2.8% | Nov 11, 2025 | Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privi... |
| CVE-2025-59511 | HIGH | 7.8 | 0.4% | Nov 11, 2025 | External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locall... |
| CVE-2025-59510 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow... |
| CVE-2025-59509 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose informatio... |
| CVE-2025-59508 | HIGH | 7 | 0.2% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an ... |
| CVE-2025-59507 | HIGH | 7 | 0.2% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an ... |
| CVE-2025-59506 | HIGH | 7 | 0.2% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an... |
| CVE-2025-59505 | HIGH | 7.8 | 0.4% | Nov 11, 2025 | Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59504 | HIGH | 7.3 | 0.3% | Nov 11, 2025 | Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. |
| CVE-2025-59499 | HIGH | 8.8 | 1.1% | Nov 11, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-59240 | MEDIUM | 5.5 | 0.6% | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to ... |
| CVE-2025-47179 | MEDIUM | 6.7 | 0.3% | Nov 11, 2025 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2025-30398 | HIGH | 8.1 | 0.8% | Nov 11, 2025 | Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-61832 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2025-61824 | HIGH | 7.8 | 0.3% | Nov 11, 2025 | InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2025-61818 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c... |
| CVE-2025-61817 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now