2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46331 | CRITICAL | 9.8 | 0.3% | Apr 30, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2025-32777 | HIGH | 8.2 | 0.4% | Apr 30, 2025 | Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology... |
| CVE-2025-2170 | HIGH | 7.2 | 0.3% | Apr 30, 2025 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, wh... |
| CVE-2025-24887 | MEDIUM | 6.3 | 0.2% | Apr 30, 2025 | OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allo... |
| CVE-2025-4135 | MEDIUM | 6.3 | 2.3% | Apr 30, 2025 | A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the funct... |
| CVE-2025-46619 | HIGH | 7.6 | 0.4% | Apr 30, 2025 | A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that ... |
| CVE-2025-44194 | HIGH | 7.3 | 0.3% | Apr 30, 2025 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p... |
| CVE-2025-44193 | HIGH | 7.6 | 0.3% | Apr 30, 2025 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p... |
| CVE-2025-44192 | CRITICAL | 9.8 | 0.4% | Apr 30, 2025 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p... |
| CVE-2025-3269 | — | — | — | Apr 30, 2025 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2025-39413 | HIGH | 8.8 | 0.3% | Apr 30, 2025 | Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This... |
| CVE-2025-33074 | HIGH | 8.8 | 0.5% | Apr 30, 2025 | Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute c... |
| CVE-2025-30392 | CRITICAL | 9.8 | 0.9% | Apr 30, 2025 | Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-30391 | HIGH | 7.5 | 1.0% | Apr 30, 2025 | Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-30390 | HIGH | 8.8 | 0.8% | Apr 30, 2025 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-30389 | CRITICAL | 9.8 | 0.7% | Apr 30, 2025 | Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-2156 | — | — | — | Apr 30, 2025 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2025-24091 | MEDIUM | 5.5 | 0.3% | Apr 30, 2025 | An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue i... |
| CVE-2025-21416 | HIGH | 8.8 | 0.6% | Apr 30, 2025 | Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-3859 | MEDIUM | 6.1 | 0.2% | Apr 30, 2025 | Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating be... |
| CVE-2025-3599 | HIGH | 7.5 | 0.2% | Apr 30, 2025 | Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevat... |
| CVE-2025-4122 | HIGH | 8.8 | 3.1% | Apr 30, 2025 | A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the f... |
| CVE-2025-46342 | HIGH | 8.2 | 0.6% | Apr 30, 2025 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it... |
| CVE-2025-32974 | CRITICAL | 9 | 0.3% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 1... |
| CVE-2025-32973 | CRITICAL | 9 | 0.3% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now