2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21064 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. |
| CVE-2025-21063 | MEDIUM | 4.6 | 0.2% | Oct 10, 2025 | Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16... |
| CVE-2025-21061 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access se... |
| CVE-2025-21060 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access ba... |
| CVE-2025-21059 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung He... |
| CVE-2025-21054 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at... |
| CVE-2025-21050 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across mult... |
| CVE-2025-21049 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive inform... |
| CVE-2025-21047 | MEDIUM | 6.8 | 0.2% | Oct 10, 2025 | Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged API... |
| CVE-2025-21045 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to acce... |
| CVE-2025-21044 | MEDIUM | 4.4 | 0.1% | Oct 10, 2025 | Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write o... |
| CVE-2025-10124 | MEDIUM | 4.5 | 0.2% | Oct 10, 2025 | The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode... |
| CVE-2025-11570 | MEDIUM | 4.6 | 0.2% | Oct 10, 2025 | Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XS... |
| CVE-2025-11450 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor... |
| CVE-2025-11449 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor... |
| CVE-2025-61926 | MEDIUM | 4.6 | 0.4% | Oct 9, 2025 | Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev... |
| CVE-2025-62240 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, a... |
| CVE-2025-61783 | MEDIUM | 6.3 | 0.5% | Oct 9, 2025 | Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, t... |
| CVE-2025-43296 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe... |
| CVE-2025-35061 | MEDIUM | 5.9 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker t... |
| CVE-2025-35060 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to u... |
| CVE-2025-35059 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl... |
| CVE-2025-35058 | MEDIUM | 5.9 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NI... |
| CVE-2025-35057 | MEDIUM | 6 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NI... |
| CVE-2025-35056 | MEDIUM | 5 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now