2025 CVE Vulnerabilities

45,250 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54098HIGH7.8Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-54097MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54096MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54095MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54094MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-54093HIGH7Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges ...
CVE-2025-54092HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an...
CVE-2025-54091HIGH7.8Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-53810MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53809MEDIUM6.5Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to...
CVE-2025-53808MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-53807HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-53806MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53805HIGH7.5Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a netwo...
CVE-2025-53804MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i...
CVE-2025-53803MEDIUM5.5Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose...
CVE-2025-53802HIGH7Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-53801HIGH7.8Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-53800HIGH7.8No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-53799MEDIUM5.5Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information local...
CVE-2025-53798MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53797MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53796MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-53348MEDIUM5.3Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control S...
CVE-2025-53340MEDIUM5.3Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now