2025 CVE Vulnerabilities

45,246 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57069HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser...
CVE-2025-57064HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpR...
CVE-2025-57063HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelP...
CVE-2025-57062HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpR...
CVE-2025-57061HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via t...
CVE-2025-57059HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule fun...
CVE-2025-57058HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the p...
CVE-2025-57057HIGH7.5Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStor...
CVE-2025-55317HIGH7.8Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attack...
CVE-2025-55316HIGH7.8External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
CVE-2025-55245HIGH7.8Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileg...
CVE-2025-55243HIGH7.5Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to p...
CVE-2025-55236HIGH7.8Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code local...
CVE-2025-55234CRITICAL9.8SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited ...
CVE-2025-55232CRITICAL9.8Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex...
CVE-2025-55228HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all...
CVE-2025-55227HIGH8.8Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized a...
CVE-2025-55226MEDIUM6.7Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an...
CVE-2025-55225MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-55224HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all...
CVE-2025-55223HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an...
CVE-2025-54919HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all...
CVE-2025-54918HIGH8.8Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-54917MEDIUM4.3Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a...
CVE-2025-54916HIGH7.8Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now