2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55339 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55338 | MEDIUM | 4.6 | 2.9% | Oct 14, 2025 | Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with... |
| CVE-2025-55337 | MEDIUM | 4.6 | 0.5% | Oct 14, 2025 | Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe... |
| CVE-2025-55336 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorize... |
| CVE-2025-55335 | HIGH | 7 | 0.2% | Oct 14, 2025 | Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-55334 | MEDIUM | 5.5 | 0.3% | Oct 14, 2025 | Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security featur... |
| CVE-2025-55333 | MEDIUM | 4.6 | 0.8% | Oct 14, 2025 | Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security fea... |
| CVE-2025-55332 | MEDIUM | 4.6 | 0.5% | Oct 14, 2025 | Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe... |
| CVE-2025-55331 | HIGH | 7 | 0.3% | Oct 14, 2025 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-55330 | MEDIUM | 4.6 | 0.5% | Oct 14, 2025 | Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security fe... |
| CVE-2025-55328 | HIGH | 7 | 0.2% | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an... |
| CVE-2025-55326 | HIGH | 7.5 | 0.8% | Oct 14, 2025 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a net... |
| CVE-2025-55325 | MEDIUM | 5.5 | 0.5% | Oct 14, 2025 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. |
| CVE-2025-55320 | MEDIUM | 6.8 | 0.6% | Oct 14, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager ... |
| CVE-2025-55315 | CRITICAL | 9.9 | 66.3% | Oct 14, 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at... |
| CVE-2025-55248 | MEDIUM | 5.7 | 0.7% | Oct 14, 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose informat... |
| CVE-2025-55247 | HIGH | 7.3 | 0.6% | Oct 14, 2025 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileg... |
| CVE-2025-55240 | HIGH | 7.3 | 0.3% | Oct 14, 2025 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54603 | MEDIUM | 6.5 | 0.6% | Oct 14, 2025 | An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat... |
| CVE-2025-53782 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to ele... |
| CVE-2025-53768 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Xbox allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53717 | HIGH | 7 | 0.3% | Oct 14, 2025 | Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an aut... |
| CVE-2025-53150 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53139 | HIGH | 7.1 | 0.3% | Oct 14, 2025 | Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security fe... |
| CVE-2025-50175 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now