2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54617CRITICAL9.8Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability c...
CVE-2025-54616MEDIUM5.5Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability m...
CVE-2025-54615MEDIUM5.5Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of thi...
CVE-2025-54614MEDIUM5.5Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may af...
CVE-2025-54613LOW3.3Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54612LOW3.3Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54611MEDIUM5.5EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-54610HIGH7.5Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54609HIGH7.5Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54608MEDIUM4Vulnerability that allows setting screen rotation direction without permission verification in the screen management mod...
CVE-2025-54607HIGH7.5Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54606HIGH7.1Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will ...
CVE-2025-54655HIGH7.8Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect...
CVE-2025-54653MEDIUM6.5Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect...
CVE-2025-54652MEDIUM5.5Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect...
CVE-2025-54884HIGH8.7Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be...
CVE-2025-54883CRITICAL9.3Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be...
CVE-2025-54879HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration...
CVE-2025-54876MEDIUM6.9The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Jansse...
CVE-2025-54873LOW2.7RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture....
CVE-2025-54872HIGH8.7onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd...
CVE-2025-54869MEDIUM6FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template...
CVE-2025-54801HIGH7.5Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParse...
CVE-2025-54594CRITICAL9.1react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/wo...
CVE-2025-54571MEDIUM6.1ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now