2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59440HIGH7.5An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2...
CVE-2025-57835HIGH7.5An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-47400HIGH7.1Cryptographic issue while copying data to a destination buffer without validating its size.
CVE-2025-47392HIGH8.8Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47391HIGH7.8Memory corruption while processing a frame request from user.
CVE-2025-47390HIGH7.8Memory corruption while preprocessing IOCTL request in JPEG driver.
CVE-2025-47389HIGH7.8Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2025-47374MEDIUM6.5Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
CVE-2025-14938MEDIUM5.3The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and ...
CVE-2025-15064MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-13368MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P...
CVE-2025-10681HIGH8.8Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end u...
CVE-2025-68153MEDIUM6.5Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-68152MEDIUM4.9Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-64340HIGH7.8FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m...
CVE-2025-59711HIGH8.3An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism,...
CVE-2025-59710HIGH8.8An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the ...
CVE-2025-59709MEDIUM6.8An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read b...
CVE-2025-7024HIGH7.3Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privileg...
CVE-2025-15620HIGH8.6HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerabil...
CVE-2025-43264HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious...
CVE-2025-43257HIGH8.7This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab...
CVE-2025-43238MEDIUM6.2An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonom...
CVE-2025-43236LOW3.3A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son...
CVE-2025-43219HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now