2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48654 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. ... |
| CVE-2025-48653 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t... |
| CVE-2025-48650 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalat... |
| CVE-2025-48646 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead... |
| CVE-2025-48645 | HIGH | 7.8 | 0.2% | Mar 2, 2026 | In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. Thi... |
| CVE-2025-48641 | HIGH | 7 | 0.1% | Mar 2, 2026 | In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local esc... |
| CVE-2025-48636 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path... |
| CVE-2025-48635 | HIGH | 7.7 | 0.1% | Mar 2, 2026 | In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er... |
| CVE-2025-48634 | HIGH | 7.3 | 0.1% | Mar 2, 2026 | In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. Th... |
| CVE-2025-48630 | HIGH | 7.4 | 0.1% | Mar 2, 2026 | In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel infor... |
| CVE-2025-48619 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate file... |
| CVE-2025-48613 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previou... |
| CVE-2025-48605 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the co... |
| CVE-2025-48602 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass... |
| CVE-2025-48582 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an ... |
| CVE-2025-48579 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confu... |
| CVE-2025-48578 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due... |
| CVE-2025-48577 | HIGH | 7.4 | 0.1% | Mar 2, 2026 | In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This ... |
| CVE-2025-48574 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du... |
| CVE-2025-48568 | HIGH | 7.4 | 0.1% | Mar 2, 2026 | In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio... |
| CVE-2025-48567 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive director... |
| CVE-2025-32313 | HIGH | 8.4 | 0.1% | Mar 2, 2026 | In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could... |
| CVE-2025-70252 | HIGH | 7.5 | 0.4% | Mar 2, 2026 | An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable... |
| CVE-2025-59603 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when processing invalid user address with nonstandard buffer address. |
| CVE-2025-59600 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when adding user-supplied data without checking available buffer space. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now