2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26437MEDIUM5.5In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credenti...
CVE-2025-26432MEDIUM5.5In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could ...
CVE-2025-26429MEDIUM5.5In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. Th...
CVE-2025-26427MEDIUM4.4In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local e...
CVE-2025-26426MEDIUM5.1In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant fo...
CVE-2025-26425MEDIUM4In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error i...
CVE-2025-26424MEDIUM4In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. Thi...
CVE-2025-26423MEDIUM6.2In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a mi...
CVE-2025-26422MEDIUM4In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to ...
CVE-2025-26421MEDIUM4In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local...
CVE-2025-26420MEDIUM4.4In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the inc...
CVE-2025-22425MEDIUM5.1In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could le...
CVE-2025-0087MEDIUM5.1In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing pe...
CVE-2025-0077MEDIUM4In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could...
CVE-2025-57576MEDIUM5.4PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
CVE-2025-38727MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_un...
CVE-2025-38726MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix potential NULL pointer access i...
CVE-2025-38725MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 md...
CVE-2025-38723MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix jump offset calculation in tail...
CVE-2025-38721MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix refcount leak on table du...
CVE-2025-38720MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix rtnl deadlock issue Currently, t...
CVE-2025-38719MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix the division by zero issue When ...
CVE-2025-38717MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net: kcm: Fix race condition in kcm_unattach() syz...
CVE-2025-38716MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hfs: fix general protection fault in hfs_find_init(...
CVE-2025-38712MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hfsplus: don't use BUG_ON() in hfsplus_create_attri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now