2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53209CRITICAL9.8Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff...
CVE-2025-52766MEDIUM6.5Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access ...
CVE-2025-52759HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Acco...
CVE-2025-5085MEDIUM5.5The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al...
CVE-2025-59614MEDIUM6.7Memory Corruption when sending random number generator command with insufficient output buffer size.
CVE-2025-59613MEDIUM6.7Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
CVE-2025-59612MEDIUM6.7Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2025-59611MEDIUM6.7Memory corruption in diagnostic services due to absence of input validation
CVE-2025-59610MEDIUM6.4Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa...
CVE-2025-59609MEDIUM5.5Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2025-59606HIGH7.8Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initi...
CVE-2025-59605HIGH7.8Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604HIGH7.8Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-59601MEDIUM6.5Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized...
CVE-2025-48652HIGH7.8In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in...
CVE-2025-48649HIGH7.8In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass...
CVE-2025-48648MEDIUM5.5In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This cou...
CVE-2025-48616LOW3.3In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning...
CVE-2025-48595HIGH8.4In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to ...
CVE-2025-48570HIGH7.8In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to...
CVE-2025-32348HIGH7.8In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead...
CVE-2025-26418HIGH7.8In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when ...
CVE-2025-22426HIGH7.8In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th...
CVE-2025-22424HIGH7.8In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul...
CVE-2025-70099HIGH7.5A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attacke...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now