2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53740 | HIGH | 8.4 | 0.5% | Aug 12, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-53739 | HIGH | 7.8 | 0.5% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker ... |
| CVE-2025-53738 | HIGH | 7.8 | 0.5% | Aug 12, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-53737 | HIGH | 7.8 | 0.5% | Aug 12, 2025 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-53736 | MEDIUM | 6.2 | 0.5% | Aug 12, 2025 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2025-53735 | HIGH | 7.8 | 0.5% | Aug 12, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-53734 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. |
| CVE-2025-53733 | HIGH | 8.4 | 0.5% | Aug 12, 2025 | Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code loca... |
| CVE-2025-53732 | HIGH | 7.8 | 0.5% | Aug 12, 2025 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-53731 | HIGH | 8.4 | 0.5% | Aug 12, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-53730 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. |
| CVE-2025-53729 | HIGH | 7.8 | 0.3% | Aug 12, 2025 | Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53728 | MEDIUM | 6.5 | 1.1% | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize... |
| CVE-2025-53727 | HIGH | 8.8 | 1.0% | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2025-53726 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke... |
| CVE-2025-53725 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke... |
| CVE-2025-53724 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke... |
| CVE-2025-53723 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53722 | HIGH | 7.5 | 17.3% | Aug 12, 2025 | Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service ove... |
| CVE-2025-53721 | HIGH | 7 | 0.3% | Aug 12, 2025 | Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally... |
| CVE-2025-53720 | HIGH | 8 | 0.8% | Aug 12, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ... |
| CVE-2025-53719 | MEDIUM | 5.7 | 1.1% | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl... |
| CVE-2025-53718 | HIGH | 7 | 0.3% | Aug 12, 2025 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2025-53716 | MEDIUM | 6.5 | 1.3% | Aug 12, 2025 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to ... |
| CVE-2025-53156 | MEDIUM | 5.5 | 0.6% | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to discl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now