2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47857MEDIUM6.7A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F...
CVE-2025-43734MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-36124HIGH7.5IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security rest...
CVE-2025-32932MEDIUM5.4An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiS...
CVE-2025-32766MEDIUM6.7A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7....
CVE-2025-27759MEDIUM6.7An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2025-25256CRITICAL9.8An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-25248MEDIUM6.5An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, v...
CVE-2025-53793HIGH7.5Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
CVE-2025-53789HIGH7.8Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate pri...
CVE-2025-53788HIGH7Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevat...
CVE-2025-53784HIGH8.4Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53783HIGH7.5Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
CVE-2025-53781MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to di...
CVE-2025-53779HIGH7.2Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2025-53778HIGH8.8Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-53773HIGH7.8Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio ...
CVE-2025-53772HIGH8.8Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
CVE-2025-53769MEDIUM5.5External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVE-2025-53766CRITICAL9.8Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2025-53765MEDIUM5.5Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclo...
CVE-2025-53761HIGH7.8Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-53760HIGH7.1Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov...
CVE-2025-53759HIGH7.8Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53741HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now