2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53155 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53154 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi... |
| CVE-2025-53153 | MEDIUM | 5.7 | 1.0% | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl... |
| CVE-2025-53152 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. |
| CVE-2025-53151 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53149 | HIGH | 7.8 | 0.7% | Aug 12, 2025 | Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privile... |
| CVE-2025-53148 | MEDIUM | 5.7 | 1.0% | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl... |
| CVE-2025-53147 | HIGH | 7 | 0.4% | Aug 12, 2025 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2025-53145 | HIGH | 8.8 | 5.6% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker t... |
| CVE-2025-53144 | HIGH | 8.8 | 5.6% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker t... |
| CVE-2025-53143 | HIGH | 8.8 | 1.0% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker t... |
| CVE-2025-53142 | HIGH | 7 | 0.3% | Aug 12, 2025 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53141 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi... |
| CVE-2025-53140 | HIGH | 7 | 0.3% | Aug 12, 2025 | Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53138 | MEDIUM | 5.7 | 1.0% | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl... |
| CVE-2025-53137 | HIGH | 7 | 0.4% | Aug 12, 2025 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2025-53136 | MEDIUM | 5.5 | 0.9% | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disc... |
| CVE-2025-53135 | HIGH | 7 | 0.2% | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an... |
| CVE-2025-53134 | HIGH | 7 | 0.3% | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio... |
| CVE-2025-53133 | HIGH | 7.8 | 0.3% | Aug 12, 2025 | Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53132 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all... |
| CVE-2025-53131 | HIGH | 8.8 | 0.8% | Aug 12, 2025 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50177 | HIGH | 8.1 | 3.6% | Aug 12, 2025 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50176 | HIGH | 7.8 | 0.4% | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execut... |
| CVE-2025-50173 | HIGH | 7.8 | 0.5% | Aug 12, 2025 | Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now