2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5572HIGH7.5A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability i...
CVE-2025-5571HIGH8.8A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSy...
CVE-2025-5569HIGH8.8A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods...
CVE-2025-4580MEDIUM4.3The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which cou...
CVE-2025-4578CRITICAL9.8The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a ...
CVE-2025-48710MEDIUM4.1kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefin...
CVE-2025-5566HIGH8.8A vulnerability classified as critical has been found in PHPGurukul Notice Board System 1.0. This affects an unknown par...
CVE-2025-5562CRITICAL9.8A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. Affected by ...
CVE-2025-5561CRITICAL9.8A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected ...
CVE-2025-5539MEDIUM6.4The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-20996MEDIUM5Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers...
CVE-2025-20995HIGH7.1Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior...
CVE-2025-20994HIGH7.1Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device p...
CVE-2025-20993MEDIUM6.8Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write o...
CVE-2025-20992HIGH7.7Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-...
CVE-2025-20991MEDIUM5.1Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to...
CVE-2025-20989MEDIUM5.2Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac...
CVE-2025-20988HIGH7.1Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out...
CVE-2025-20987MEDIUM6.7Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get...
CVE-2025-20986MEDIUM5.5Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take...
CVE-2025-20985LOW3.3Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse...
CVE-2025-20984MEDIUM6.2Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to...
CVE-2025-20981MEDIUM6.2Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive infor...
CVE-2025-5560CRITICAL9.8A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been classified as critical. Affecte...
CVE-2025-5558HIGH8.8A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. Thi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now