2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45058 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. T... |
| CVE-2025-45057 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp funct... |
| CVE-2025-56015 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. |
| CVE-2025-14859 | HIGH | 7 | 0.1% | Apr 7, 2026 | The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmwa... |
| CVE-2025-14821 | HIGH | 7 | 0.1% | Apr 7, 2026 | A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secur... |
| CVE-2025-24818 | HIGH | 8 | 1.0% | Apr 7, 2026 | Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme... |
| CVE-2025-24817 | HIGH | 8 | 1.0% | Apr 7, 2026 | Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme... |
| CVE-2025-39666 | HIGH | 7.3 | 0.1% | Apr 7, 2026 | Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Che... |
| CVE-2025-54601 | HIGH | 7 | 0.1% | Apr 6, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 12... |
| CVE-2025-57834 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 12... |
| CVE-2025-54602 | HIGH | 7 | 0.1% | Apr 6, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12... |
| CVE-2025-54324 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-59440 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2... |
| CVE-2025-57835 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-47400 | HIGH | 7.1 | 0.1% | Apr 6, 2026 | Cryptographic issue while copying data to a destination buffer without validating its size. |
| CVE-2025-47392 | HIGH | 8.8 | 0.2% | Apr 6, 2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. |
| CVE-2025-47391 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory corruption while processing a frame request from user. |
| CVE-2025-47390 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory corruption while preprocessing IOCTL request in JPEG driver. |
| CVE-2025-47389 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. |
| CVE-2025-10681 | HIGH | 8.8 | 0.3% | Apr 3, 2026 | Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end u... |
| CVE-2025-64340 | HIGH | 7.8 | 0.7% | Apr 3, 2026 | FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m... |
| CVE-2025-59711 | HIGH | 8.3 | 0.7% | Apr 3, 2026 | An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism,... |
| CVE-2025-59710 | HIGH | 8.8 | 0.5% | Apr 3, 2026 | An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the ... |
| CVE-2025-7024 | HIGH | 7.3 | 0.1% | Apr 3, 2026 | Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privileg... |
| CVE-2025-15620 | HIGH | 8.6 | 0.5% | Apr 2, 2026 | HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerabil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now