2025 CVE Vulnerabilities

45,225 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20932MEDIUM5.5Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻rea...
CVE-2025-20930MEDIUM5.5Out-of-bounds read in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-...
CVE-2025-20928MEDIUM5.5Out-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access o...
CVE-2025-20927MEDIUM5.5Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access o...
CVE-2025-20926MEDIUM5.5Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local atta...
CVE-2025-20925MEDIUM5.5Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to...
CVE-2025-20924MEDIUM4.6Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across mult...
CVE-2025-20923MEDIUM4Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary a...
CVE-2025-20913MEDIUM5.5Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to...
CVE-2025-20912MEDIUM6.2Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data withi...
CVE-2025-20911MEDIUM4.4Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update ...
CVE-2025-20910MEDIUM6.2Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access da...
CVE-2025-20909MEDIUM5.5Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to...
CVE-2025-20908MEDIUM6.5Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Aura...
CVE-2025-1979MEDIUM6.4Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the r...
CVE-2025-27625MEDIUM4.3In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered...
CVE-2025-27624MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers...
CVE-2025-27623MEDIUM4.3Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xm...
CVE-2025-27622MEDIUM4.3Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xm...
CVE-2025-25634MEDIUM6.5A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetPar...
CVE-2025-20208MEDIUM5.4A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-pri...
CVE-2025-27412MEDIUM6.1REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected ...
CVE-2025-27411MEDIUM5.4REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. Thi...
CVE-2025-24521MEDIUM6.9External XML entity injection allows arbitrary download of files. The score without least privilege principle violation...
CVE-2025-23416MEDIUM6.9Path traversal may lead to arbitrary file deletion. The score without least privilege principle violation is as calcula...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now