2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48574HIGH8.4In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du...
CVE-2025-48568HIGH7.4In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio...
CVE-2025-48567HIGH7.8In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive director...
CVE-2025-32313HIGH8.4In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could...
CVE-2025-70252HIGH7.5An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable...
CVE-2025-64427MEDIUM6.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio...
CVE-2025-59603HIGH7.8Memory Corruption when processing invalid user address with nonstandard buffer address.
CVE-2025-59600HIGH7.8Memory Corruption when adding user-supplied data without checking available buffer space.
CVE-2025-47386HIGH7.8Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47385HIGH7.8Memory Corruption when accessing trusted execution environment without proper privilege check.
CVE-2025-47384MEDIUM6.5Transient DOS when MAC configures config id greater than supported maximum value.
CVE-2025-47383HIGH7.2Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47381HIGH7.8Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47379HIGH7.8Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and ...
CVE-2025-47378HIGH7.1Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
CVE-2025-47377HIGH7.8Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
CVE-2025-47376HIGH7.8Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
CVE-2025-47375HIGH7.8Memory corruption while handling different IOCTL calls from the user-space simultaneously.
CVE-2025-47373HIGH7.8Memory Corruption when accessing buffers with invalid length during TA invocation.
CVE-2025-47371MEDIUM6.5Transient DOS when an LTE RLC packet with invalid TB is received by UE.
CVE-2025-66880MEDIUM6.1Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute...
CVE-2025-52998CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor...
CVE-2025-52564MEDIUM6.1Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani...
CVE-2025-52563MEDIUM6.1Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne...
CVE-2025-52476MEDIUM6.1Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now