2025 CVE Vulnerabilities
45,169 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58179 | MEDIUM | 6.5 | 0.8% | Sep 5, 2025 | Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using A... |
| CVE-2025-55739 | MEDIUM | 5.1 | 0.5% | Sep 5, 2025 | api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower t... |
| CVE-2025-55305 | MEDIUM | 6.1 | 0.3% | Sep 4, 2025 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions belo... |
| CVE-2025-55209 | MEDIUM | 5.1 | 0.3% | Sep 4, 2025 | contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versi... |
| CVE-2025-22415 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local ... |
| CVE-2025-48562 | MEDIUM | 5 | 0.1% | Sep 4, 2025 | In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could... |
| CVE-2025-48561 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to access data displayed on the screen due to side channel information di... |
| CVE-2025-48560 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could... |
| CVE-2025-48559 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val... |
| CVE-2025-48554 | MEDIUM | 6.1 | 0.1% | Sep 4, 2025 | In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a l... |
| CVE-2025-48551 | MEDIUM | 5 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused... |
| CVE-2025-48550 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path trav... |
| CVE-2025-48542 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh... |
| CVE-2025-48538 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa... |
| CVE-2025-48529 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused... |
| CVE-2025-48528 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead... |
| CVE-2025-48527 | MEDIUM | 6.2 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the cod... |
| CVE-2025-48526 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActi... |
| CVE-2025-48524 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This c... |
| CVE-2025-32330 | MEDIUM | 5.7 | 0.1% | Sep 4, 2025 | In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio str... |
| CVE-2025-26463 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This c... |
| CVE-2025-26456 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in... |
| CVE-2025-26453 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic er... |
| CVE-2025-26449 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo... |
| CVE-2025-26448 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now