2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65804 | MEDIUM | 6.5 | 0.5% | Dec 8, 2025 | Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corru... |
| CVE-2025-48608 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check... |
| CVE-2025-48569 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo... |
| CVE-2025-14259 | MEDIUM | 6.3 | 0.2% | Dec 8, 2025 | A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functiona... |
| CVE-2025-65799 | MEDIUM | 4.3 | 0.2% | Dec 8, 2025 | A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to e... |
| CVE-2025-65797 | MEDIUM | 6.5 | 0.3% | Dec 8, 2025 | Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level priv... |
| CVE-2025-59391 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patche... |
| CVE-2025-48633 | MEDIUM | 5.5 | 0.2% | Dec 8, 2025 | In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisio... |
| CVE-2025-48631 | MEDIUM | 6.5 | 0.5% | Dec 8, 2025 | In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti... |
| CVE-2025-48622 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead... |
| CVE-2025-48618 | MEDIUM | 6.8 | 0.1% | Dec 8, 2025 | In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to... |
| CVE-2025-48614 | MEDIUM | 4.6 | 0.1% | Dec 8, 2025 | In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due ... |
| CVE-2025-48610 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in... |
| CVE-2025-48607 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. Thi... |
| CVE-2025-48604 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c... |
| CVE-2025-48603 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. ... |
| CVE-2025-48601 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead... |
| CVE-2025-48600 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple files, there is a possible way to reveal information across users due to a missing permission check. This co... |
| CVE-2025-48598 | MEDIUM | 6.6 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy... |
| CVE-2025-48591 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c... |
| CVE-2025-48590 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency... |
| CVE-2025-48584 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limi... |
| CVE-2025-48576 | MEDIUM | 5.5 | 0.1% | Dec 8, 2025 | In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanen... |
| CVE-2025-32319 | MEDIUM | 6.7 | 0.1% | Dec 8, 2025 | In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions d... |
| CVE-2025-22432 | MEDIUM | 6.7 | 0.1% | Dec 8, 2025 | In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input valid... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now