2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0510 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that ... |
| CVE-2025-24860 | MEDIUM | 5.4 | 1.0% | Feb 4, 2025 | Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they s... |
| CVE-2025-20907 | MEDIUM | 4.4 | 0.1% | Feb 4, 2025 | Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disab... |
| CVE-2025-20906 | MEDIUM | 5.5 | 0.1% | Feb 4, 2025 | Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to ... |
| CVE-2025-20905 | MEDIUM | 6.7 | 0.1% | Feb 4, 2025 | Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to r... |
| CVE-2025-20904 | MEDIUM | 6.7 | 0.1% | Feb 4, 2025 | Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memo... |
| CVE-2025-20902 | MEDIUM | 5.1 | 0.1% | Feb 4, 2025 | Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in M... |
| CVE-2025-20901 | MEDIUM | 4.4 | 0.1% | Feb 4, 2025 | Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bou... |
| CVE-2025-20900 | MEDIUM | 4.4 | 0.1% | Feb 4, 2025 | Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-b... |
| CVE-2025-20899 | MEDIUM | 4 | 0.1% | Feb 4, 2025 | Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1... |
| CVE-2025-20898 | MEDIUM | 4.6 | 0.2% | Feb 4, 2025 | Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across ... |
| CVE-2025-20897 | MEDIUM | 6.8 | 0.1% | Feb 4, 2025 | Improper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 ... |
| CVE-2025-20896 | MEDIUM | 5.5 | 0.1% | Feb 4, 2025 | Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to acces... |
| CVE-2025-20895 | MEDIUM | 4.6 | 0.2% | Feb 4, 2025 | Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to ins... |
| CVE-2025-20894 | MEDIUM | 4.6 | 0.2% | Feb 4, 2025 | Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multi... |
| CVE-2025-20893 | MEDIUM | 5.1 | 0.1% | Feb 4, 2025 | Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the conf... |
| CVE-2025-20892 | MEDIUM | 5.9 | 0.2% | Feb 4, 2025 | Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute... |
| CVE-2025-20891 | MEDIUM | 5.5 | 0.1% | Feb 4, 2025 | Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 a... |
| CVE-2025-20889 | MEDIUM | 5.5 | 0.1% | Feb 4, 2025 | Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows lo... |
| CVE-2025-20887 | MEDIUM | 5.5 | 0.1% | Feb 4, 2025 | Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attack... |
| CVE-2025-20886 | MEDIUM | 4.4 | 0.1% | Feb 4, 2025 | Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privile... |
| CVE-2025-20885 | MEDIUM | 6.7 | 0.1% | Feb 4, 2025 | Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memor... |
| CVE-2025-20884 | MEDIUM | 4.6 | 0.2% | Feb 4, 2025 | Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data acro... |
| CVE-2025-20883 | MEDIUM | 4.6 | 0.2% | Feb 4, 2025 | Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across m... |
| CVE-2025-0466 | MEDIUM | 5.3 | 0.4% | Feb 4, 2025 | The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now