2025 CVE Vulnerabilities

45,254 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9502CRITICAL9.8A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the f...
CVE-2025-7732MEDIUM6.4The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers...
CVE-2025-8490MEDIUM4.4The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import ...
CVE-2025-9277MEDIUM6.4The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_repla...
CVE-2025-57820HIGH7.9Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object ...
CVE-2025-35115CRITICAL9.2Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Midd...
CVE-2025-35114HIGH8.7Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The p...
CVE-2025-35113HIGH7.2Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticat...
CVE-2025-35112MEDIUM4.9Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an...
CVE-2025-26417MEDIUM4In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening fil...
CVE-2025-22413MEDIUM4In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This cou...
CVE-2025-22412HIGH8.8In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could ...
CVE-2025-22411HIGH8.8In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. Th...
CVE-2025-22410HIGH8.4In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc...
CVE-2025-22409HIGH8.4In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This...
CVE-2025-22408CRITICAL9.8In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This c...
CVE-2025-22407MEDIUM5.5In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. Th...
CVE-2025-22406HIGH8.4In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. ...
CVE-2025-22405HIGH8.4In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc...
CVE-2025-22404HIGH8.4In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This ...
CVE-2025-22403CRITICAL9.8In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after ...
CVE-2025-0093HIGH7.5In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission...
CVE-2025-0092MEDIUM6.5In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien...
CVE-2025-0086MEDIUM6.2In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c...
CVE-2025-0084HIGH8.8In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now