2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27733HIGH7.8Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-27732HIGH7Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate pri...
CVE-2025-27731HIGH7.8Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
CVE-2025-27730HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-27729HIGH7.8Use after free in Windows Shell allows an unauthorized attacker to execute code locally.
CVE-2025-27728HIGH7.8Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2025-27727HIGH7.8Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele...
CVE-2025-27492HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel al...
CVE-2025-27491HIGH7.1Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
CVE-2025-27490HIGH7.8Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-27489HIGH7.8Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
CVE-2025-27487HIGH8Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2025-27486HIGH7.5Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ...
CVE-2025-27485HIGH7.5Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ...
CVE-2025-27484HIGH7.5Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an autho...
CVE-2025-27483HIGH7.8Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-27482HIGH8.1Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to ...
CVE-2025-27481HIGH8.8Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27480HIGH8.1Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27479HIGH7.5Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
CVE-2025-27478HIGH7Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges...
CVE-2025-27477HIGH8.8Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27476HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-27475HIGH7Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate priv...
CVE-2025-27473HIGH7.5Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now