2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70252 | HIGH | 7.5 | 0.4% | Mar 2, 2026 | An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable... |
| CVE-2025-64427 | MEDIUM | 6.5 | 0.2% | Mar 2, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio... |
| CVE-2025-59603 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when processing invalid user address with nonstandard buffer address. |
| CVE-2025-59600 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when adding user-supplied data without checking available buffer space. |
| CVE-2025-47386 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. |
| CVE-2025-47385 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. |
| CVE-2025-47384 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | Transient DOS when MAC configures config id greater than supported maximum value. |
| CVE-2025-47383 | HIGH | 7.2 | 0.1% | Mar 2, 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |
| CVE-2025-47381 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs. |
| CVE-2025-47379 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and ... |
| CVE-2025-47378 | HIGH | 7.1 | 0.1% | Mar 2, 2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. |
| CVE-2025-47377 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. |
| CVE-2025-47376 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls. |
| CVE-2025-47375 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory corruption while handling different IOCTL calls from the user-space simultaneously. |
| CVE-2025-47373 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. |
| CVE-2025-47371 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. |
| CVE-2025-66880 | MEDIUM | 6.1 | 0.3% | Mar 2, 2026 | Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute... |
| CVE-2025-52998 | CRITICAL | 9.8 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor... |
| CVE-2025-52564 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani... |
| CVE-2025-52563 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52476 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52475 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne... |
| CVE-2025-52470 | MEDIUM | 4.8 | 0.2% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi... |
| CVE-2025-52469 | HIGH | 7.1 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow ... |
| CVE-2025-52468 | MEDIUM | 6.1 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now