2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48595HIGH8.4In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to ...
CVE-2025-48570HIGH7.8In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to...
CVE-2025-32348HIGH7.8In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead...
CVE-2025-26418HIGH7.8In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when ...
CVE-2025-22426HIGH7.8In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th...
CVE-2025-22424HIGH7.8In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul...
CVE-2025-70099HIGH7.5A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attacke...
CVE-2025-60495MEDIUM5.5A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box befo...
CVE-2025-60486MEDIUM5.5A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows at...
CVE-2025-60485MEDIUM5.5A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before...
CVE-2025-60483MEDIUM5.5A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Pro...
CVE-2025-60481MEDIUM5.5A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.0...
CVE-2025-55664MEDIUM5.5A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to ...
CVE-2025-41281HIGH7.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41280HIGH7.8Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9....
CVE-2025-41279HIGH7.2Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41278HIGH7.8Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R260114104...
CVE-2025-41277CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41276CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41275CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41274CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41273CRITICAL9.8Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI...
CVE-2025-41272CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41271HIGH7.5Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hos...
CVE-2025-41270CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now