2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-29810HIGH7.5Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a n...
CVE-2025-29809HIGH7.1Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature...
CVE-2025-29805HIGH7.5Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to dis...
CVE-2025-29804HIGH7.3Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-29802HIGH7.3Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-29801HIGH7.8Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-29800HIGH7.8Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-29794HIGH8.8Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-29793HIGH7.2Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne...
CVE-2025-29792HIGH7.3Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2025-29791HIGH7.8Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe...
CVE-2025-27752HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27751HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27750HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27749HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27748HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27747HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-27746HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27745HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-27744HIGH7.8Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2025-27743HIGH7.8Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
CVE-2025-27741HIGH7.8Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-27740HIGH8.8Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges...
CVE-2025-27739HIGH7.8Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-27737HIGH8.6Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now