2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20659 | MEDIUM | 6.5 | 0.3% | Apr 7, 2025 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2025-20658 | MEDIUM | 6 | 0.1% | Apr 7, 2025 | In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if ... |
| CVE-2025-20657 | MEDIUM | 6.7 | 0.1% | Apr 7, 2025 | In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of ... |
| CVE-2025-20656 | MEDIUM | 6.8 | 0.1% | Apr 7, 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri... |
| CVE-2025-20655 | MEDIUM | 5.3 | 0.1% | Apr 7, 2025 | In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information... |
| CVE-2025-27534 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-25057 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-24304 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write. |
| CVE-2025-22842 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2025-22452 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2025-20102 | MEDIUM | 5.5 | 0.1% | Apr 7, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2025-3327 | MEDIUM | 6.1 | 0.3% | Apr 7, 2025 | A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown proc... |
| CVE-2025-3326 | MEDIUM | 5.1 | 0.4% | Apr 7, 2025 | A vulnerability has been found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This vulnerability affects unkn... |
| CVE-2025-3325 | MEDIUM | 5.3 | 0.4% | Apr 6, 2025 | A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part... |
| CVE-2025-31488 | MEDIUM | 4.9 | 0.2% | Apr 6, 2025 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If ... |
| CVE-2025-3318 | MEDIUM | 6.3 | 0.3% | Apr 6, 2025 | A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected b... |
| CVE-2025-3317 | MEDIUM | 5.3 | 0.5% | Apr 6, 2025 | A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14... |
| CVE-2025-32369 | MEDIUM | 5.4 | 0.2% | Apr 6, 2025 | Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certai... |
| CVE-2025-1264 | MEDIUM | 6.5 | 0.4% | Apr 6, 2025 | The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to... |
| CVE-2025-3305 | MEDIUM | 5.3 | 0.4% | Apr 5, 2025 | A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerab... |
| CVE-2025-32366 | MEDIUM | 4.8 | 0.4% | Apr 5, 2025 | In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=n... |
| CVE-2025-32364 | MEDIUM | 5.5 | 0.2% | Apr 5, 2025 | A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash whe... |
| CVE-2025-32358 | MEDIUM | 4.1 | 0.2% | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are trigger... |
| CVE-2025-32357 | MEDIUM | 4.3 | 0.2% | Apr 5, 2025 | In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to f... |
| CVE-2025-30401 | MEDIUM | 6.7 | 15.8% | Apr 5, 2025 | A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type bu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now