Skip to main content

Year archive

CVEs published in 2025

Archive summary

48,163 CVEs published in 2025 — 4,093 Critical, 16,161 High, 23,604 Medium, 3,395 Low, 910 Unrated.

CVE-2024-9140

Published Jan 3, 2025

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection du…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2024-9138

Published Jan 3, 2025

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded crede…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-12132

Published Jan 3, 2025

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22275

Published Jan 3, 2025

iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can oc…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-53842

Published Jan 3, 2025

In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no addition…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53841

Published Jan 3, 2025

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional executi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53840

Published Jan 3, 2025

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53839

Published Jan 3, 2025

In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53838

Published Jan 3, 2025

In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53837

Published Jan 3, 2025

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53836

Published Jan 3, 2025

In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System exec…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53835

Published Jan 3, 2025

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53834

Published Jan 3, 2025

In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53833

Published Jan 3, 2025

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47032

Published Jan 3, 2025

In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11624

Published Jan 3, 2025

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0175

Published Jan 3, 2025

A vulnerability was found in code-projects Online Shop 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view.php. The manipulation of…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2024-43769

Published Jan 3, 2025

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This coul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43768

Published Jan 3, 2025

In skia_alloc_func of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execut…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43767

Published Jan 3, 2025

In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remote code execution with no addi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-43764

Published Jan 3, 2025

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional exe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43762

Published Jan 3, 2025

In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. This could lead to local escalation of privilege w…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 47,901-47,925 of 48,163 CVEsPage 1917 of 1927