2025 CVE Vulnerabilities

45,268 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27563MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVE-2025-27247MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVE-2025-27242MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
CVE-2025-27131MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
CVE-2025-26693MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVE-2025-26691MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVE-2025-25217MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2025-24493MEDIUM4.7in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.
CVE-2025-23235MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.
CVE-2025-21082MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2025-20063MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2025-38004HIGH7.1In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates T...
CVE-2025-38003MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procf...
CVE-2025-5242Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5223Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5097Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5026Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-5840HIGH7.3A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Th...
CVE-2025-5839HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is th...
CVE-2025-5838HIGH8.8A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this v...
CVE-2025-5837HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is a...
CVE-2025-5836MEDIUM6.3A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formS...
CVE-2025-49619HIGH8.5Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc...
CVE-2025-5568MEDIUM5.4The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions ...
CVE-2025-5528MEDIUM6.1The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now