2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-24443HIGH7.8Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r...
CVE-2025-24442HIGH7.8Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-24441HIGH7.8Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-24440HIGH7.8Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-24439HIGH7.8Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r...
CVE-2025-0151HIGH8.8Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via net...
CVE-2025-27172HIGH7.8Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result ...
CVE-2025-26645HIGH8.8Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-26634HIGH7.5Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.
CVE-2025-26633HIGH7Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature loc...
CVE-2025-26631HIGH7.3Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
CVE-2025-26630HIGH7.8Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2025-26629HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-26627HIGH7Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized at...
CVE-2025-25008HIGH7.1Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to ele...
CVE-2025-25003HIGH7.3Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-24998HIGH7.3Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-24995HIGH7.8Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privile...
CVE-2025-24994HIGH7.3Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVE-2025-24993HIGH7.8Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2025-24985HIGH7.8Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
CVE-2025-24983HIGH7Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2025-24084HIGH8.4Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
CVE-2025-24083HIGH7.8Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-24082HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now