2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59241 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allow... |
| CVE-2025-59238 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-59237 | HIGH | 8.8 | 2.2% | Oct 14, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2025-59236 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-59235 | HIGH | 7.1 | 0.6% | Oct 14, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2025-59234 | HIGH | 7.8 | 0.5% | Oct 14, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-59233 | HIGH | 7.8 | 0.5% | Oct 14, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ... |
| CVE-2025-59232 | HIGH | 7.1 | 0.4% | Oct 14, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2025-59231 | HIGH | 7.8 | 0.5% | Oct 14, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ... |
| CVE-2025-59230 | HIGH | 7.8 | 2.6% | Oct 14, 2025 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ... |
| CVE-2025-59229 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. |
| CVE-2025-59228 | HIGH | 8.8 | 1.2% | Oct 14, 2025 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-59227 | HIGH | 7.8 | 0.5% | Oct 14, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-59226 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. |
| CVE-2025-59225 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-59224 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-59223 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-59222 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-59221 | HIGH | 7 | 0.4% | Oct 14, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-59214 | MEDIUM | 6.5 | 1.8% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p... |
| CVE-2025-59213 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ... |
| CVE-2025-59211 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack... |
| CVE-2025-59210 | HIGH | 7.4 | 0.3% | Oct 14, 2025 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
| CVE-2025-59209 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack... |
| CVE-2025-59208 | HIGH | 7.1 | 0.5% | Oct 14, 2025 | Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now