2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9990HIGH8.1The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
CVE-2025-58362HIGH7.5Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 conta...
CVE-2025-55242HIGH7.5Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati...
CVE-2025-55238HIGH7.5Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-58353HIGH8.2Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version...
CVE-2025-32322HIGH7.8In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin...
CVE-2025-26439HIGH7.8In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to b...
CVE-2025-26431HIGH7.8In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility se...
CVE-2025-22414HIGH7.8In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permiss...
CVE-2025-48581HIGH8.4In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the...
CVE-2025-48563HIGH7.8In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default va...
CVE-2025-48558HIGH7.8In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app ...
CVE-2025-48556HIGH7.3In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper ...
CVE-2025-48553HIGH7.8In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er...
CVE-2025-48552HIGH7.8In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a...
CVE-2025-48549HIGH7.8In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T...
CVE-2025-48548HIGH7.3In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva...
CVE-2025-48547HIGH7.3In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead ...
CVE-2025-48546HIGH7.8In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in ...
CVE-2025-48545HIGH7.1In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf...
CVE-2025-48544HIGH7.8In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le...
CVE-2025-48543HIGH8.8In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft...
CVE-2025-48541HIGH7.8In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope...
CVE-2025-48540HIGH7.8In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co...
CVE-2025-48539HIGH8In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now