2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-48654HIGH7.8In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. ...
CVE-2025-48653HIGH7.8In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t...
CVE-2025-48650HIGH8.4In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalat...
CVE-2025-48646HIGH7.8In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead...
CVE-2025-48645HIGH7.8In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. Thi...
CVE-2025-48641HIGH7In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local esc...
CVE-2025-48636HIGH8.4In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path...
CVE-2025-48635HIGH7.7In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er...
CVE-2025-48634HIGH7.3In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. Th...
CVE-2025-48630HIGH7.4In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel infor...
CVE-2025-48619HIGH8.4In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate file...
CVE-2025-48613HIGH7.8In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previou...
CVE-2025-48605HIGH8.4In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the co...
CVE-2025-48602HIGH8.4In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass...
CVE-2025-48582HIGH8.4In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an ...
CVE-2025-48579HIGH8.4In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confu...
CVE-2025-48578HIGH7.8In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due...
CVE-2025-48577HIGH7.4In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This ...
CVE-2025-48574HIGH8.4In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du...
CVE-2025-48568HIGH7.4In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio...
CVE-2025-48567HIGH7.8In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive director...
CVE-2025-32313HIGH8.4In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could...
CVE-2025-70252HIGH7.5An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable...
CVE-2025-59603HIGH7.8Memory Corruption when processing invalid user address with nonstandard buffer address.
CVE-2025-59600HIGH7.8Memory Corruption when adding user-supplied data without checking available buffer space.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now