2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55339HIGH7.8Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.
CVE-2025-55338MEDIUM4.6Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with...
CVE-2025-55337MEDIUM4.6Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe...
CVE-2025-55336MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorize...
CVE-2025-55335HIGH7Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2025-55334MEDIUM5.5Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security featur...
CVE-2025-55333MEDIUM4.6Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security fea...
CVE-2025-55332MEDIUM4.6Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe...
CVE-2025-55331HIGH7Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.
CVE-2025-55330MEDIUM4.6Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe...
CVE-2025-55328HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an...
CVE-2025-55326HIGH7.5Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net...
CVE-2025-55325MEDIUM5.5Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-55320MEDIUM6.8Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ...
CVE-2025-55315CRITICAL9.9Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at...
CVE-2025-55248MEDIUM5.7Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose informat...
CVE-2025-55247HIGH7.3Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileg...
CVE-2025-55240HIGH7.3Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-54603MEDIUM6.5An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat...
CVE-2025-53782HIGH7.8Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to ele...
CVE-2025-53768HIGH7.8Use after free in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-53717HIGH7Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an aut...
CVE-2025-53150HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-53139HIGH7.1Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security fe...
CVE-2025-50175HIGH7.8Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now