2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20942MEDIUM4.4Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local at...
CVE-2025-20940MEDIUM4Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 al...
CVE-2025-20939MEDIUM5.4Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical att...
CVE-2025-20938MEDIUM5.5Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected da...
CVE-2025-20935MEDIUM5.5Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo...
CVE-2025-20934MEDIUM5.5Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files w...
CVE-2025-3406MEDIUM6.5A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function...
CVE-2025-3405MEDIUM5.3A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by...
CVE-2025-3403MEDIUM5.1A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been...
CVE-2025-3364MEDIUM6.7The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to...
CVE-2025-32413MEDIUM6.4Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.
CVE-2025-3397MEDIUM6.1A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess...
CVE-2025-3393MEDIUM5.1A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been cla...
CVE-2025-3392MEDIUM6.1A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue ...
CVE-2025-2519MEDIUM6.5The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T...
CVE-2025-3391MEDIUM6.1A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this v...
CVE-2025-3390MEDIUM6.1A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the...
CVE-2025-3389MEDIUM6.1A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue...
CVE-2025-3388MEDIUM6.1A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects ...
CVE-2025-3387MEDIUM5.4A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknow...
CVE-2025-3386MEDIUM4.8A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some un...
CVE-2025-3385MEDIUM4.8A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability...
CVE-2025-32029MEDIUM6.9ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding ca...
CVE-2025-3382MEDIUM6.3A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and...
CVE-2025-29769MEDIUM5.5libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly de...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now