2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2776CRITICAL9.8SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the S...
CVE-2025-2775HIGH7.5SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the C...
CVE-2025-29448HIGH7.5Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively ...
CVE-2025-29602MEDIUM6.1flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.
CVE-2025-29154MEDIUM6.5HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via...
CVE-2025-29153MEDIUM5.4SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via ...
CVE-2025-29152HIGH7.6Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary co...
CVE-2025-33093HIGH7.5IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored...
CVE-2025-4104CRITICAL9.8The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t...
CVE-2025-39361MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Ele...
CVE-2025-27533HIGH7.5Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands...
CVE-2025-20980MEDIUM5.5Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
CVE-2025-20979HIGH7.8Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
CVE-2025-20978MEDIUM6.2Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.
CVE-2025-20977LOW3.3Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows loc...
CVE-2025-20976HIGH7.5Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to re...
CVE-2025-20975MEDIUM5.5Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to lau...
CVE-2025-20974MEDIUM6.1Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to b...
CVE-2025-20973MEDIUM5.4Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows phy...
CVE-2025-20972MEDIUM5.5Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers t...
CVE-2025-20971MEDIUM5.5Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung...
CVE-2025-20970MEDIUM6.2Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 ...
CVE-2025-20969MEDIUM5.5Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android...
CVE-2025-20968CRITICAL9.1Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1...
CVE-2025-20967CRITICAL9.1Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now