2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20753 | MEDIUM | 5.3 | 0.4% | Dec 2, 2025 | In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if... |
| CVE-2025-20752 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i... |
| CVE-2025-20751 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i... |
| CVE-2025-20750 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2025-13697 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ... |
| CVE-2025-12529 | HIGH | 8.8 | 0.5% | Dec 2, 2025 | The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ... |
| CVE-2025-58488 | MEDIUM | 6.5 | 0.4% | Dec 2, 2025 | Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote atta... |
| CVE-2025-58487 | LOW | 3.3 | 0.1% | Dec 2, 2025 | Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity ... |
| CVE-2025-58486 | MEDIUM | 5.5 | 0.1% | Dec 2, 2025 | Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary scrip... |
| CVE-2025-58485 | MEDIUM | 5.5 | 0.1% | Dec 2, 2025 | Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary scri... |
| CVE-2025-58484 | MEDIUM | 4 | 0.1% | Dec 2, 2025 | Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access parti... |
| CVE-2025-58483 | LOW | 3.3 | 0.1% | Dec 2, 2025 | Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows loc... |
| CVE-2025-58482 | HIGH | 7.3 | 0.1% | Dec 2, 2025 | Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privile... |
| CVE-2025-58481 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privil... |
| CVE-2025-58480 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access o... |
| CVE-2025-58479 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bo... |
| CVE-2025-58478 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-b... |
| CVE-2025-58477 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers... |
| CVE-2025-58476 | MEDIUM | 4.6 | 0.1% | Dec 2, 2025 | Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-o... |
| CVE-2025-58475 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write ou... |
| CVE-2025-55129 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulner... |
| CVE-2025-21080 | HIGH | 7.1 | 0.1% | Dec 2, 2025 | Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local att... |
| CVE-2025-21072 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged... |
| CVE-2025-66448 | HIGH | 8.8 | 0.6% | Dec 1, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote co... |
| CVE-2025-66415 | MEDIUM | 5.4 | 0.1% | Dec 1, 2025 | fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafti... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now