2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26668HIGH7.5Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-26666HIGH7.8Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
CVE-2025-26665HIGH7Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate priv...
CVE-2025-26663HIGH8.1Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code o...
CVE-2025-26652HIGH7.5Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ...
CVE-2025-26649HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel al...
CVE-2025-26648HIGH7.8Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges...
CVE-2025-26647HIGH8.8Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2025-26642HIGH7.8Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-26641HIGH7.5Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over...
CVE-2025-26640HIGH7Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-26639HIGH7.8Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-24074HIGH7.8Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-24073HIGH7.8Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-24062HIGH7.8Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-24060HIGH7.8Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-24058HIGH7.8Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-21222HIGH8.8Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-21221HIGH8.8Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-21205HIGH8.8Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-21204HIGH7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to ...
CVE-2025-21191HIGH7Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacke...
CVE-2025-21174HIGH7.5Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ...
CVE-2025-32117HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetiz...
CVE-2025-27083HIGH7.2Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now