2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69369 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-68886 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58897 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58707 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58705 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58024 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53440 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53345 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress ... |
| CVE-2025-52759 | HIGH | 7.1 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Acco... |
| CVE-2025-59606 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initi... |
| CVE-2025-59605 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory Corruption when processing device identifier strings that exceed the expected maximum length. |
| CVE-2025-59604 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. |
| CVE-2025-48652 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in... |
| CVE-2025-48649 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass... |
| CVE-2025-48595 | HIGH | 8.4 | 1.7% | Jun 1, 2026 | In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to ... |
| CVE-2025-48570 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to... |
| CVE-2025-32348 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead... |
| CVE-2025-26418 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when ... |
| CVE-2025-22426 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th... |
| CVE-2025-22424 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul... |
| CVE-2025-70099 | HIGH | 7.5 | 0.4% | Jun 1, 2026 | A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attacke... |
| CVE-2025-41281 | HIGH | 7.8 | 0.5% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41280 | HIGH | 7.8 | 0.1% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.... |
| CVE-2025-41279 | HIGH | 7.2 | 0.9% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41278 | HIGH | 7.8 | 0.1% | May 29, 2026 | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R260114104... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now