2025 CVE Vulnerabilities
45,225 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20932 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻rea... |
| CVE-2025-20930 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Out-of-bounds read in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-... |
| CVE-2025-20928 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Out-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access o... |
| CVE-2025-20927 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access o... |
| CVE-2025-20926 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local atta... |
| CVE-2025-20925 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to... |
| CVE-2025-20924 | MEDIUM | 4.6 | 0.2% | Mar 6, 2025 | Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across mult... |
| CVE-2025-20923 | MEDIUM | 4 | 0.1% | Mar 6, 2025 | Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary a... |
| CVE-2025-20913 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to... |
| CVE-2025-20912 | MEDIUM | 6.2 | 0.1% | Mar 6, 2025 | Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data withi... |
| CVE-2025-20911 | MEDIUM | 4.4 | 0.1% | Mar 6, 2025 | Improper access control in sem_wifi service prior to SMR Mar-2025 Release 1 allows privileged local attackers to update ... |
| CVE-2025-20910 | MEDIUM | 6.2 | 0.1% | Mar 6, 2025 | Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access da... |
| CVE-2025-20909 | MEDIUM | 5.5 | 0.1% | Mar 6, 2025 | Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to... |
| CVE-2025-20908 | MEDIUM | 6.5 | 0.3% | Mar 6, 2025 | Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Aura... |
| CVE-2025-1979 | MEDIUM | 6.4 | 0.2% | Mar 6, 2025 | Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the r... |
| CVE-2025-27625 | MEDIUM | 4.3 | 0.6% | Mar 5, 2025 | In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered... |
| CVE-2025-27624 | MEDIUM | 5.4 | 0.4% | Mar 5, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers... |
| CVE-2025-27623 | MEDIUM | 4.3 | 0.3% | Mar 5, 2025 | Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xm... |
| CVE-2025-27622 | MEDIUM | 4.3 | 0.7% | Mar 5, 2025 | Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xm... |
| CVE-2025-25634 | MEDIUM | 6.5 | 0.3% | Mar 5, 2025 | A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetPar... |
| CVE-2025-20208 | MEDIUM | 5.4 | 0.2% | Mar 5, 2025 | A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-pri... |
| CVE-2025-27412 | MEDIUM | 6.1 | 0.3% | Mar 5, 2025 | REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected ... |
| CVE-2025-27411 | MEDIUM | 5.4 | 0.3% | Mar 5, 2025 | REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. Thi... |
| CVE-2025-24521 | MEDIUM | 6.9 | 0.4% | Mar 5, 2025 | External XML entity injection allows arbitrary download of files. The score without least privilege principle violation... |
| CVE-2025-23416 | MEDIUM | 6.9 | 0.5% | Mar 5, 2025 | Path traversal may lead to arbitrary file deletion. The score without least privilege principle violation is as calcula... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now