2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47324HIGH7.5Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
CVE-2025-27076HIGH7Memory corruption while processing simultaneous requests via escape path.
CVE-2025-27075HIGH7.8Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.
CVE-2025-27073HIGH7.5Transient DOS while creating NDP instance.
CVE-2025-27069HIGH7.8Memory corruption while processing DDI command calls.
CVE-2025-27068HIGH7.8Memory corruption while processing an IOCTL command with an arbitrary address.
CVE-2025-27067HIGH7.8Memory corruption while processing DDI call with invalid buffer.
CVE-2025-27066HIGH7.5Transient DOS while processing an ANQP message.
CVE-2025-27065HIGH7.5Transient DOS while processing a frame with malformed shared-key descriptor.
CVE-2025-27062HIGH7.8Memory corruption while handling client exceptions, allowing unauthorized channel access.
CVE-2025-21477HIGH7.5Transient DOS while processing CCCH data when NW sends data with invalid length.
CVE-2025-21474HIGH7.8Memory corruption while processing commands from A2dp sink command queue.
CVE-2025-21473HIGH7Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
CVE-2025-21461HIGH7.8Memory corruption when programming registers through virtual CDM.
CVE-2025-21458HIGH7.8Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.
CVE-2025-21456HIGH7.8Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
CVE-2025-21455HIGH7.8Memory corruption while submitting blob data to kernel space though IOCTL.
CVE-2025-21452HIGH7.5Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2025-21015HIGH7.1Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document s...
CVE-2025-8420HIGH8.1Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code ...
CVE-2025-54635HIGH7.5Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of...
CVE-2025-54630HIGH7.5:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulne...
CVE-2025-54628HIGH7.5Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of thi...
CVE-2025-54627HIGH8.8Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-8654HIGH8.8Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now