2025 CVE Vulnerabilities

45,252 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9842HIGH7.5A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the fil...
CVE-2025-9841HIGH8.8A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown f...
CVE-2025-9260MEDIUM6.5The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2025-54588HIGH7.5Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Version...
CVE-2025-9840CRITICAL9.8A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function...
CVE-2025-9839CRITICAL9.8A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a...
CVE-2025-9838CRITICAL9.8A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown functio...
CVE-2025-26416CRITICAL9.8In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. ...
CVE-2025-22442HIGH7In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications i...
CVE-2025-22439HIGH7.3In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps ...
CVE-2025-22438HIGH7.8In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local...
CVE-2025-22437HIGH7.8In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due ...
CVE-2025-22435CRITICAL9.8In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired d...
CVE-2025-22434HIGH7.8In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the ...
CVE-2025-22433HIGH7.8In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most common...
CVE-2025-22431MEDIUM5.5In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limite...
CVE-2025-22430MEDIUM5.5In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing perm...
CVE-2025-22429CRITICAL9.8In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could le...
CVE-2025-22428HIGH7.8In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on t...
CVE-2025-22427HIGH7.3In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above t...
CVE-2025-22423HIGH7.5In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This coul...
CVE-2025-22422HIGH7.8In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app whe...
CVE-2025-22421MEDIUM5.5In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak throug...
CVE-2025-22419HIGH7.3In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to...
CVE-2025-22418HIGH7.8In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now