2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20966 | MEDIUM | 4.6 | 0.2% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20965 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access ... |
| CVE-2025-20964 | HIGH | 7.8 | 0.1% | May 7, 2025 | Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to wri... |
| CVE-2025-20963 | HIGH | 7.8 | 0.1% | May 7, 2025 | Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to w... |
| CVE-2025-20962 | MEDIUM | 4 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attacke... |
| CVE-2025-20961 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows lo... |
| CVE-2025-20960 | LOW | 3.3 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attacker... |
| CVE-2025-20959 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local att... |
| CVE-2025-20958 | MEDIUM | 4.4 | 0.1% | May 7, 2025 | Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attacke... |
| CVE-2025-20957 | HIGH | 7.8 | 0.1% | May 7, 2025 | Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary act... |
| CVE-2025-20956 | MEDIUM | 4.3 | 0.2% | May 7, 2025 | Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows phy... |
| CVE-2025-20955 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 al... |
| CVE-2025-20954 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attacker... |
| CVE-2025-20953 | MEDIUM | 4.4 | 0.1% | May 7, 2025 | Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities wi... |
| CVE-2025-20949 | CRITICAL | 9.1 | 0.3% | May 7, 2025 | Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary ... |
| CVE-2025-20937 | MEDIUM | 6.7 | 0.1% | May 7, 2025 | Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out... |
| CVE-2025-4171 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2025-0669 | HIGH | 8.8 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOI... |
| CVE-2025-0668 | CRITICAL | 9.8 | 0.5% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
| CVE-2025-0667 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
| CVE-2025-0666 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
| CVE-2025-32405 | HIGH | 7.5 | 0.5% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that... |
| CVE-2025-32404 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ... |
| CVE-2025-32403 | CRITICAL | 9.8 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices ... |
| CVE-2025-32402 | HIGH | 7.5 | 0.3% | May 7, 2025 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now