2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36931 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea... |
| CVE-2025-36930 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea... |
| CVE-2025-36929 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. T... |
| CVE-2025-36928 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could ... |
| CVE-2025-36927 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. ... |
| CVE-2025-36925 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In WAVES_send_data_to_dsp of libaoc_waves.c, there is a possible out of bounds write due to a missing bounds check. This... |
| CVE-2025-36924 | HIGH | 8 | 0.1% | Dec 11, 2025 | In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect... |
| CVE-2025-36923 | HIGH | 8 | 0.1% | Dec 11, 2025 | In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap... |
| CVE-2025-36922 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to loc... |
| CVE-2025-36921 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds ch... |
| CVE-2025-36919 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In aocc_read of aoc_channel_dev.c, there is a possible double free due to improper locking. This could lead to local esc... |
| CVE-2025-36918 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. ... |
| CVE-2025-36917 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This... |
| CVE-2025-36916 | HIGH | 7 | 0.1% | Dec 11, 2025 | In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lea... |
| CVE-2025-36912 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote den... |
| CVE-2025-36889 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead... |
| CVE-2025-14536 | CRITICAL | 9.8 | 0.5% | Dec 11, 2025 | A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerabi... |
| CVE-2025-14535 | CRITICAL | 9.8 | 4.9% | Dec 11, 2025 | A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/... |
| CVE-2025-13481 | HIGH | 8.8 | 0.4% | Dec 11, 2025 | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevate... |
| CVE-2025-13214 | HIGH | 8.8 | 0.3% | Dec 11, 2025 | IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially craft... |
| CVE-2025-13211 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email ... |
| CVE-2025-13148 | MEDIUM | 6.5 | 0.2% | Dec 11, 2025 | IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another us... |
| CVE-2025-12532 | — | — | — | Dec 11, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-56130 | HIGH | 8.8 | 1.8% | Dec 11, 2025 | OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary ... |
| CVE-2025-56129 | HIGH | 8.8 | 2.3% | Dec 11, 2025 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a cra... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now