2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27563 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-27247 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-27242 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-27131 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-26693 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-26691 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-25217 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |
| CVE-2025-24493 | MEDIUM | 4.7 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition. |
| CVE-2025-23235 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2025-21082 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2025-20063 | MEDIUM | 5.5 | 0.1% | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2025-38004 | HIGH | 7.1 | 0.2% | Jun 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates T... |
| CVE-2025-38003 | MEDIUM | 5.5 | 0.2% | Jun 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procf... |
| CVE-2025-5242 | — | — | — | Jun 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-5223 | — | — | — | Jun 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-5097 | — | — | — | Jun 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-5026 | — | — | — | Jun 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-5840 | HIGH | 7.3 | 0.4% | Jun 7, 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Th... |
| CVE-2025-5839 | HIGH | 8.8 | 0.8% | Jun 7, 2025 | A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is th... |
| CVE-2025-5838 | HIGH | 8.8 | 0.3% | Jun 7, 2025 | A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this v... |
| CVE-2025-5837 | HIGH | 8.8 | 0.3% | Jun 7, 2025 | A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is a... |
| CVE-2025-5836 | MEDIUM | 6.3 | 3.0% | Jun 7, 2025 | A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formS... |
| CVE-2025-49619 | HIGH | 8.5 | 13.7% | Jun 7, 2025 | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc... |
| CVE-2025-5568 | MEDIUM | 5.4 | 0.2% | Jun 7, 2025 | The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions ... |
| CVE-2025-5528 | MEDIUM | 6.1 | 0.2% | Jun 7, 2025 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now