2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65964HIGH8.8n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to...
CVE-2025-65271HIGH8.8Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te...
CVE-2025-14261HIGH7.1The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only...
CVE-2025-48625HIGH7In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen ...
CVE-2025-48606HIGH7.8In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi...
CVE-2025-65795HIGH7.5Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create ...
CVE-2025-65363HIGH7.2Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app...
CVE-2025-63721HIGH8.8HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit ...
CVE-2025-48639HIGH7.3In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking...
CVE-2025-48638HIGH7.8In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could ...
CVE-2025-48637HIGH7.8In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could l...
CVE-2025-48632HIGH7.8In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the use...
CVE-2025-48629HIGH7.8In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech reco...
CVE-2025-48628HIGH7.8In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused dep...
CVE-2025-48627HIGH7.8In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the ...
CVE-2025-48624HIGH7.8In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This c...
CVE-2025-48623HIGH7.8In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could le...
CVE-2025-48621HIGH7.3In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This ...
CVE-2025-48620HIGH7.8In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's...
CVE-2025-48615HIGH7.8In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaust...
CVE-2025-48612HIGH7.8In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's defau...
CVE-2025-48599HIGH7.8In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to...
CVE-2025-48597HIGH7.8In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay a...
CVE-2025-48596HIGH7.8In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to lo...
CVE-2025-48594HIGH7.3In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now