2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-20918HIGH7.5Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers t...
CVE-2025-20917HIGH7.5Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to rea...
CVE-2025-20916HIGH7.5Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of...
CVE-2025-20915HIGH7.5Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to r...
CVE-2025-20914HIGH7.5Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attacke...
CVE-2025-20903HIGH7.3Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch priv...
CVE-2025-24864HIGH7.8Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5...
CVE-2025-22447HIGH7.8Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1....
CVE-2025-27508HIGH7.5Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum...
CVE-2025-27516HIGH8.8Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts ...
CVE-2025-2003HIGH7.1Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass...
CVE-2025-27513HIGH7.5OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 coul...
CVE-2025-20206HIGH7.8A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authen...
CVE-2025-27497HIGH8.7OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability ...
CVE-2025-24494HIGH8.6Path traversal may allow remote code execution using privileged account (requires device admin account, cannot be perfo...
CVE-2025-1702HIGH7.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-0956HIGH8.1The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,...
CVE-2025-27685HIGH7.5Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration Fi...
CVE-2025-27684HIGH7.5Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Con...
CVE-2025-27683HIGH8.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestric...
CVE-2025-27669HIGH7.5Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network ...
CVE-2025-27664HIGH8.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CS...
CVE-2025-27644HIGH7.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege...
CVE-2025-27639HIGH8.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Esca...
CVE-2025-1919HIGH8.8Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now