2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21064MEDIUM6.5Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
CVE-2025-21063MEDIUM4.6Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16...
CVE-2025-21061MEDIUM5.5Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access se...
CVE-2025-21060MEDIUM5.5Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access ba...
CVE-2025-21059MEDIUM5.5Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung He...
CVE-2025-21054MEDIUM5.5Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at...
CVE-2025-21050MEDIUM5.5Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across mult...
CVE-2025-21049MEDIUM5.5Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive inform...
CVE-2025-21047MEDIUM6.8Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged API...
CVE-2025-21045MEDIUM5.5Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to acce...
CVE-2025-21044MEDIUM4.4Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write o...
CVE-2025-10124MEDIUM4.5The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode...
CVE-2025-11570MEDIUM4.6Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XS...
CVE-2025-11450MEDIUM5.3ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor...
CVE-2025-11449MEDIUM5.3ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor...
CVE-2025-61926MEDIUM4.6Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev...
CVE-2025-62240MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, a...
CVE-2025-61783MEDIUM6.3Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, t...
CVE-2025-43296MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe...
CVE-2025-35061MEDIUM5.9Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker t...
CVE-2025-35060MEDIUM5.4Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to u...
CVE-2025-35059MEDIUM6.1Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl...
CVE-2025-35058MEDIUM5.9Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NI...
CVE-2025-35057MEDIUM6Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NI...
CVE-2025-35056MEDIUM5Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now