2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20942 | MEDIUM | 4.4 | 0.1% | Apr 8, 2025 | Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local at... |
| CVE-2025-20940 | MEDIUM | 4 | 0.1% | Apr 8, 2025 | Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 al... |
| CVE-2025-20939 | MEDIUM | 5.4 | 0.2% | Apr 8, 2025 | Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical att... |
| CVE-2025-20938 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected da... |
| CVE-2025-20935 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows lo... |
| CVE-2025-20934 | MEDIUM | 5.5 | 0.1% | Apr 8, 2025 | Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files w... |
| CVE-2025-3406 | MEDIUM | 6.5 | 0.5% | Apr 8, 2025 | A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function... |
| CVE-2025-3405 | MEDIUM | 5.3 | 0.3% | Apr 8, 2025 | A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by... |
| CVE-2025-3403 | MEDIUM | 5.1 | 0.3% | Apr 8, 2025 | A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been... |
| CVE-2025-3364 | MEDIUM | 6.7 | 0.2% | Apr 8, 2025 | The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to... |
| CVE-2025-32413 | MEDIUM | 6.4 | 0.2% | Apr 8, 2025 | Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py. |
| CVE-2025-3397 | MEDIUM | 6.1 | 0.4% | Apr 8, 2025 | A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file mess... |
| CVE-2025-3393 | MEDIUM | 5.1 | 0.3% | Apr 8, 2025 | A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been cla... |
| CVE-2025-3392 | MEDIUM | 6.1 | 0.2% | Apr 8, 2025 | A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue ... |
| CVE-2025-2519 | MEDIUM | 6.5 | 0.4% | Apr 8, 2025 | The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T... |
| CVE-2025-3391 | MEDIUM | 6.1 | 0.3% | Apr 8, 2025 | A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this v... |
| CVE-2025-3390 | MEDIUM | 6.1 | 0.2% | Apr 8, 2025 | A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the... |
| CVE-2025-3389 | MEDIUM | 6.1 | 0.3% | Apr 8, 2025 | A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue... |
| CVE-2025-3388 | MEDIUM | 6.1 | 0.3% | Apr 7, 2025 | A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects ... |
| CVE-2025-3387 | MEDIUM | 5.4 | 0.3% | Apr 7, 2025 | A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknow... |
| CVE-2025-3386 | MEDIUM | 4.8 | 0.3% | Apr 7, 2025 | A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some un... |
| CVE-2025-3385 | MEDIUM | 4.8 | 0.3% | Apr 7, 2025 | A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability... |
| CVE-2025-32029 | MEDIUM | 6.9 | 0.2% | Apr 7, 2025 | ts-asn1-der is a collection of utility classes to encode ASN.1 data following DER rule. Incorrect number DER encoding ca... |
| CVE-2025-3382 | MEDIUM | 6.3 | 0.3% | Apr 7, 2025 | A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and... |
| CVE-2025-29769 | MEDIUM | 5.5 | 0.2% | Apr 7, 2025 | libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly de... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now