2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20659MEDIUM6.5In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2025-20658MEDIUM6In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if ...
CVE-2025-20657MEDIUM6.7In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of ...
CVE-2025-20656MEDIUM6.8In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri...
CVE-2025-20655MEDIUM5.3In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information...
CVE-2025-27534MEDIUM5.5in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2025-25057MEDIUM5.5in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2025-24304MEDIUM5.5in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds write.
CVE-2025-22842MEDIUM5.5in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
CVE-2025-22452MEDIUM5.5in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
CVE-2025-20102MEDIUM5.5in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
CVE-2025-3327MEDIUM6.1A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown proc...
CVE-2025-3326MEDIUM5.1A vulnerability has been found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This vulnerability affects unkn...
CVE-2025-3325MEDIUM5.3A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part...
CVE-2025-31488MEDIUM4.9Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If ...
CVE-2025-3318MEDIUM6.3A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected b...
CVE-2025-3317MEDIUM5.3A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14...
CVE-2025-32369MEDIUM5.4Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certai...
CVE-2025-1264MEDIUM6.5The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to...
CVE-2025-3305MEDIUM5.3A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerab...
CVE-2025-32366MEDIUM4.8In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=n...
CVE-2025-32364MEDIUM5.5A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash whe...
CVE-2025-32358MEDIUM4.1In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are trigger...
CVE-2025-32357MEDIUM4.3In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to f...
CVE-2025-30401MEDIUM6.7A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type bu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now