2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-21069HIGH7.1Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to ac...
CVE-2025-21068HIGH7.1Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to ac...
CVE-2025-21067HIGH7.1Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers ...
CVE-2025-21066HIGH7.1Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-o...
CVE-2025-21062HIGH7.8Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to rep...
CVE-2025-21058HIGH7.3Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attack...
CVE-2025-21055HIGH7.5Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access...
CVE-2025-21053HIGH7.8Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local a...
CVE-2025-21052HIGH7.8Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 ...
CVE-2025-21051HIGH7.8Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at...
CVE-2025-21048HIGH7.8Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary c...
CVE-2025-61871HIGH8.4NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w...
CVE-2025-61779HIGH8.7Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing ...
CVE-2025-61773HIGH8.1pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte...
CVE-2025-61602HIGH7.5BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 a...
CVE-2025-61601HIGH7.5BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 a...
CVE-2025-60375HIGH7.3The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient...
CVE-2025-59271HIGH8.7Redis Enterprise Elevation of Privilege Vulnerability
CVE-2025-35055HIGH8.8Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar...
CVE-2025-34248HIGH7.2D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/globa...
CVE-2025-11554HIGH8.8A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown f...
CVE-2025-59146HIGH8.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticate...
CVE-2025-4615HIGH7.2An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar...
CVE-2025-11552HIGH8.8A vulnerability was identified in code-projects Online Complaint Site 1.0. This impacts an unknown function of the file ...
CVE-2025-11573HIGH8.7An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of servic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now