2025 CVE Vulnerabilities

45,155 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2415HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas...
CVE-2025-9817HIGH7.5SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
CVE-2025-21034HIGH7.8Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitr...
CVE-2025-9785HIGH7.7PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment a...
CVE-2025-58176HIGH8.8Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9...
CVE-2025-9848HIGH7.5A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is ...
CVE-2025-58163HIGH8.8FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain ...
CVE-2025-9843HIGH7.5A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Opera...
CVE-2025-9842HIGH7.5A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the fil...
CVE-2025-9841HIGH8.8A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown f...
CVE-2025-54588HIGH7.5Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Version...
CVE-2025-22442HIGH7In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications i...
CVE-2025-22439HIGH7.3In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps ...
CVE-2025-22438HIGH7.8In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local...
CVE-2025-22437HIGH7.8In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due ...
CVE-2025-22434HIGH7.8In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the ...
CVE-2025-22433HIGH7.8In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most common...
CVE-2025-22428HIGH7.8In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on t...
CVE-2025-22427HIGH7.3In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above t...
CVE-2025-22423HIGH7.5In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This coul...
CVE-2025-22422HIGH7.8In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app whe...
CVE-2025-22419HIGH7.3In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to...
CVE-2025-22418HIGH7.8In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation o...
CVE-2025-22417HIGH7.3In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacki...
CVE-2025-22416HIGH7.8In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now