2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2776 | CRITICAL | 9.8 | 73.0% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S... |
| CVE-2025-2775 | HIGH | 7.5 | 55.2% | May 7, 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the C... |
| CVE-2025-29448 | HIGH | 7.5 | 0.5% | May 7, 2025 | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively ... |
| CVE-2025-29602 | MEDIUM | 6.1 | 0.2% | May 7, 2025 | flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories. |
| CVE-2025-29154 | MEDIUM | 6.5 | 0.4% | May 7, 2025 | HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via... |
| CVE-2025-29153 | MEDIUM | 5.4 | 0.3% | May 7, 2025 | SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via ... |
| CVE-2025-29152 | HIGH | 7.6 | 0.3% | May 7, 2025 | Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary co... |
| CVE-2025-33093 | HIGH | 7.5 | 0.3% | May 7, 2025 | IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored... |
| CVE-2025-4104 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t... |
| CVE-2025-39361 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Ele... |
| CVE-2025-27533 | HIGH | 7.5 | 8.6% | May 7, 2025 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands... |
| CVE-2025-20980 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption. |
| CVE-2025-20979 | HIGH | 7.8 | 0.1% | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code. |
| CVE-2025-20978 | MEDIUM | 6.2 | 0.1% | May 7, 2025 | Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege. |
| CVE-2025-20977 | LOW | 3.3 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows loc... |
| CVE-2025-20976 | HIGH | 7.5 | 0.2% | May 7, 2025 | Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to re... |
| CVE-2025-20975 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to lau... |
| CVE-2025-20974 | MEDIUM | 6.1 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to b... |
| CVE-2025-20973 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows phy... |
| CVE-2025-20972 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers t... |
| CVE-2025-20971 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung... |
| CVE-2025-20970 | MEDIUM | 6.2 | 0.1% | May 7, 2025 | Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 ... |
| CVE-2025-20969 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android... |
| CVE-2025-20968 | CRITICAL | 9.1 | 0.3% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20967 | CRITICAL | 9.1 | 0.2% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now