2025 CVE Vulnerabilities
45,250 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54098 | HIGH | 7.8 | 2.6% | Sep 9, 2025 | Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54097 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-54096 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-54095 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-54094 | MEDIUM | 6.7 | 0.4% | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ... |
| CVE-2025-54093 | HIGH | 7 | 0.3% | Sep 9, 2025 | Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges ... |
| CVE-2025-54092 | HIGH | 7.8 | 0.3% | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an... |
| CVE-2025-54091 | HIGH | 7.8 | 0.4% | Sep 9, 2025 | Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53810 | MEDIUM | 6.7 | 0.4% | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ... |
| CVE-2025-53809 | MEDIUM | 6.5 | 1.4% | Sep 9, 2025 | Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to... |
| CVE-2025-53808 | MEDIUM | 6.7 | 0.4% | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ... |
| CVE-2025-53807 | HIGH | 7 | 0.3% | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon... |
| CVE-2025-53806 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53805 | HIGH | 7.5 | 1.3% | Sep 9, 2025 | Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a netwo... |
| CVE-2025-53804 | MEDIUM | 5.5 | 0.6% | Sep 9, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i... |
| CVE-2025-53803 | MEDIUM | 5.5 | 0.6% | Sep 9, 2025 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose... |
| CVE-2025-53802 | HIGH | 7 | 0.4% | Sep 9, 2025 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53801 | HIGH | 7.8 | 0.4% | Sep 9, 2025 | Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53800 | HIGH | 7.8 | 0.5% | Sep 9, 2025 | No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53799 | MEDIUM | 5.5 | 0.7% | Sep 9, 2025 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information local... |
| CVE-2025-53798 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53797 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53796 | MEDIUM | 6.5 | 1.1% | Sep 9, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa... |
| CVE-2025-53348 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-53340 | MEDIUM | 5.3 | 0.3% | Sep 9, 2025 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now