2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26668 | HIGH | 7.5 | 1.1% | Apr 8, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-26666 | HIGH | 7.8 | 0.6% | Apr 8, 2025 | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. |
| CVE-2025-26665 | HIGH | 7 | 0.3% | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate priv... |
| CVE-2025-26663 | HIGH | 8.1 | 1.8% | Apr 8, 2025 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code o... |
| CVE-2025-26652 | HIGH | 7.5 | 1.9% | Apr 8, 2025 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ... |
| CVE-2025-26649 | HIGH | 7 | 0.3% | Apr 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel al... |
| CVE-2025-26648 | HIGH | 7.8 | 0.4% | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges... |
| CVE-2025-26647 | HIGH | 8.8 | 1.9% | Apr 8, 2025 | Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-26642 | HIGH | 7.8 | 0.7% | Apr 8, 2025 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-26641 | HIGH | 7.5 | 1.9% | Apr 8, 2025 | Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over... |
| CVE-2025-26640 | HIGH | 7 | 0.4% | Apr 8, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
| CVE-2025-26639 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24074 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24073 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24062 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24060 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24058 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2025-21222 | HIGH | 8.8 | 1.2% | Apr 8, 2025 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-21221 | HIGH | 8.8 | 1.2% | Apr 8, 2025 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-21205 | HIGH | 8.8 | 1.2% | Apr 8, 2025 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-21204 | HIGH | 7.8 | 6.4% | Apr 8, 2025 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to ... |
| CVE-2025-21191 | HIGH | 7 | 0.3% | Apr 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacke... |
| CVE-2025-21174 | HIGH | 7.5 | 1.7% | Apr 8, 2025 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker ... |
| CVE-2025-32117 | HIGH | 7.1 | 0.2% | Apr 8, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetiz... |
| CVE-2025-27083 | HIGH | 7.2 | 1.1% | Apr 8, 2025 | Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now