2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59207HIGH7.8Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-59206HIGH7.4Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59205HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-59204MEDIUM5.5Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information local...
CVE-2025-59203MEDIUM5.5Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclos...
CVE-2025-59202HIGH7Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2025-59201HIGH7.8Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privilege...
CVE-2025-59200HIGH7.7Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Clie...
CVE-2025-59199HIGH7.8Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locall...
CVE-2025-59198MEDIUM5Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
CVE-2025-59197MEDIUM5.5Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose inform...
CVE-2025-59196HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allo...
CVE-2025-59195HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-59194HIGH7Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-59193HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic...
CVE-2025-59192HIGH7.8Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-59191HIGH7.8Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privi...
CVE-2025-59190MEDIUM5.5Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
CVE-2025-59189HIGH7Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVE-2025-59188MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to ...
CVE-2025-59187HIGH7.8Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-59186MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i...
CVE-2025-59185MEDIUM6.5External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n...
CVE-2025-59184MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized at...
CVE-2025-58739MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now