2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53694HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), S...
CVE-2025-53693CRITICAL9.8Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Ex...
CVE-2025-53691HIGH8.8Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a...
CVE-2025-3701MEDIUM4.3Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting...
CVE-2025-38678MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on up...
CVE-2025-41000LOW2.1Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits...
CVE-2025-9821LOW2.7SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, t...
CVE-2025-9219MEDIUM4.3The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo,...
CVE-2025-2415HIGH8.6Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas...
CVE-2025-1740CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas...
CVE-2025-9817HIGH7.5SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
CVE-2025-9378MEDIUM6.4The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-8663MEDIUM6.5Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know...
CVE-2025-58210CRITICAL9.8Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access C...
CVE-2025-58272LOW3.7Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views ...
CVE-2025-21041MEDIUM5.5Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitiv...
CVE-2025-21040LOW3.3Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attacker...
CVE-2025-21039LOW3.3Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local...
CVE-2025-21038LOW3.3Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows loca...
CVE-2025-21037MEDIUM4.3Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across mult...
CVE-2025-21036MEDIUM5Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported...
CVE-2025-21035MEDIUM4.6Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows...
CVE-2025-21034HIGH7.8Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitr...
CVE-2025-21033MEDIUM5.5Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive in...
CVE-2025-21032MEDIUM6.8Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode un...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now