2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57834HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 12...
CVE-2025-54602HIGH7An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-54328CRITICAL10An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-58349CRITICAL9.1An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-54324HIGH7.5An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-48651MEDIUM5.5In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr...
CVE-2025-61166MEDIUM6.1An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted ...
CVE-2025-59440HIGH7.5An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2...
CVE-2025-57835HIGH7.5An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-47400HIGH7.1Cryptographic issue while copying data to a destination buffer without validating its size.
CVE-2025-47392HIGH8.8Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47391HIGH7.8Memory corruption while processing a frame request from user.
CVE-2025-47390HIGH7.8Memory corruption while preprocessing IOCTL request in JPEG driver.
CVE-2025-47389HIGH7.8Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2025-47374MEDIUM6.5Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
CVE-2025-14938MEDIUM5.3The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and ...
CVE-2025-15064MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-13368MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P...
CVE-2025-10681HIGH8.8Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end u...
CVE-2025-68153MEDIUM6.5Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-68152MEDIUM4.9Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-64340HIGH7.8FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m...
CVE-2025-59711HIGH8.3An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism,...
CVE-2025-59710HIGH8.8An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the ...
CVE-2025-59709MEDIUM6.8An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now