2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9990 | HIGH | 8.1 | 0.7% | Sep 5, 2025 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and... |
| CVE-2025-58362 | HIGH | 7.5 | 0.5% | Sep 5, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 conta... |
| CVE-2025-55242 | HIGH | 7.5 | 0.7% | Sep 4, 2025 | Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati... |
| CVE-2025-55238 | HIGH | 7.5 | 0.8% | Sep 4, 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability |
| CVE-2025-58353 | HIGH | 8.2 | 0.2% | Sep 4, 2025 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version... |
| CVE-2025-32322 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin... |
| CVE-2025-26439 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to b... |
| CVE-2025-26431 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility se... |
| CVE-2025-22414 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permiss... |
| CVE-2025-48581 | HIGH | 8.4 | 0.2% | Sep 4, 2025 | In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the... |
| CVE-2025-48563 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default va... |
| CVE-2025-48558 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app ... |
| CVE-2025-48556 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper ... |
| CVE-2025-48553 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er... |
| CVE-2025-48552 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a... |
| CVE-2025-48549 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T... |
| CVE-2025-48548 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva... |
| CVE-2025-48547 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead ... |
| CVE-2025-48546 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in ... |
| CVE-2025-48545 | HIGH | 7.1 | 0.1% | Sep 4, 2025 | In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf... |
| CVE-2025-48544 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le... |
| CVE-2025-48543 | HIGH | 8.8 | 0.5% | Sep 4, 2025 | In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft... |
| CVE-2025-48541 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope... |
| CVE-2025-48540 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co... |
| CVE-2025-48539 | HIGH | 8 | 0.2% | Sep 4, 2025 | In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now