2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61506CRITICAL9.8An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of ...
CVE-2025-60865HIGH7.8Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate priv...
CVE-2025-59439HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920...
CVE-2025-58348MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58347MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58346MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58345MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58344MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58343MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58342MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58341MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58340MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-57529CRITICAL9.8YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to...
CVE-2025-52629MEDIUM6.1HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cr...
CVE-2025-52627HIGH7.5Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critic...
CVE-2025-52626CRITICAL9.8A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially ...
CVE-2025-46651MEDIUM4.3Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due...
CVE-2025-65017MEDIUM6.5Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0...
CVE-2025-5319CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics a...
CVE-2025-14550HIGH7.5An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att...
CVE-2025-13473MEDIUM5.3An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers...
CVE-2025-7760HIGH7.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ofisimo Web...
CVE-2025-6397HIGH8.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Host...
CVE-2025-11598LOW1In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal informat...
CVE-2025-67857MEDIUM5.3A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now