2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29153 | MEDIUM | 5.4 | 0.3% | May 7, 2025 | SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via ... |
| CVE-2025-39361 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Ele... |
| CVE-2025-20980 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption. |
| CVE-2025-20978 | MEDIUM | 6.2 | 0.1% | May 7, 2025 | Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege. |
| CVE-2025-20975 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to lau... |
| CVE-2025-20974 | MEDIUM | 6.1 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to b... |
| CVE-2025-20973 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows phy... |
| CVE-2025-20972 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers t... |
| CVE-2025-20971 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung... |
| CVE-2025-20970 | MEDIUM | 6.2 | 0.1% | May 7, 2025 | Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 ... |
| CVE-2025-20969 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android... |
| CVE-2025-20966 | MEDIUM | 4.6 | 0.2% | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 1... |
| CVE-2025-20965 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access ... |
| CVE-2025-20962 | MEDIUM | 4 | 0.1% | May 7, 2025 | Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attacke... |
| CVE-2025-20961 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows lo... |
| CVE-2025-20959 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local att... |
| CVE-2025-20958 | MEDIUM | 4.4 | 0.1% | May 7, 2025 | Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attacke... |
| CVE-2025-20956 | MEDIUM | 4.3 | 0.2% | May 7, 2025 | Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows phy... |
| CVE-2025-20955 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 al... |
| CVE-2025-20954 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attacker... |
| CVE-2025-20953 | MEDIUM | 4.4 | 0.1% | May 7, 2025 | Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities wi... |
| CVE-2025-20937 | MEDIUM | 6.7 | 0.1% | May 7, 2025 | Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out... |
| CVE-2025-4171 | MEDIUM | 6.4 | 0.2% | May 7, 2025 | The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2025-0667 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
| CVE-2025-0666 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Serve... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now