2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59289HIGH7Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59288MEDIUM5.3Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi...
CVE-2025-59287CRITICAL9.8Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over ...
CVE-2025-59285HIGH7Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-59284MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp...
CVE-2025-59282HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows ...
CVE-2025-59281HIGH7.8Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to ...
CVE-2025-59280LOW3.1Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
CVE-2025-59278HIGH7.8Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat...
CVE-2025-59277HIGH7.8Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat...
CVE-2025-59275HIGH7.8Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat...
CVE-2025-59261HIGH7Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to eleva...
CVE-2025-59260MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author...
CVE-2025-59259MEDIUM6.5Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d...
CVE-2025-59258MEDIUM6.2Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker...
CVE-2025-59257MEDIUM6.5Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d...
CVE-2025-59255HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-59254HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-59253MEDIUM5.5Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
CVE-2025-59250HIGH8.1Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a netwo...
CVE-2025-59249HIGH8.8Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-59248HIGH7.5Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a networ...
CVE-2025-59244MEDIUM6.5External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n...
CVE-2025-59243HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59242HIGH7.8Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now