2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50172MEDIUM6.5Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service ov...
CVE-2025-50171CRITICAL9.1Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-50170HIGH7.8Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authoriz...
CVE-2025-50169HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an una...
CVE-2025-50168HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to...
CVE-2025-50167HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an...
CVE-2025-50166MEDIUM6.5Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose ...
CVE-2025-50165CRITICAL9.8Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a net...
CVE-2025-50164HIGH8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ...
CVE-2025-50163HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-50162HIGH8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ...
CVE-2025-50161HIGH7.3Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2025-50160HIGH8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute ...
CVE-2025-50159HIGH7.3Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privilege...
CVE-2025-50158HIGH7Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose informatio...
CVE-2025-50157MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-50156MEDIUM5.7Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to discl...
CVE-2025-50155HIGH7.8Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke...
CVE-2025-50154MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p...
CVE-2025-50153HIGH7.8Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-49762HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio...
CVE-2025-49761HIGH7.8Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-49759HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2025-49758HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2025-49757HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now