2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32964 | MEDIUM | 4.6 | 0.2% | Apr 22, 2025 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting... |
| CVE-2025-32963 | MEDIUM | 6.9 | 0.5% | Apr 22, 2025 | MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided f... |
| CVE-2025-32961 | MEDIUM | 6.4 | 0.3% | Apr 22, 2025 | The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTT... |
| CVE-2025-32960 | MEDIUM | 6.4 | 0.3% | Apr 22, 2025 | The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which co... |
| CVE-2025-32959 | MEDIUM | 6.5 | 0.4% | Apr 22, 2025 | CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file... |
| CVE-2025-32952 | MEDIUM | 6.5 | 0.6% | Apr 22, 2025 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ... |
| CVE-2025-32951 | MEDIUM | 5.4 | 0.3% | Apr 22, 2025 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ... |
| CVE-2025-32950 | MEDIUM | 6.5 | 0.6% | Apr 22, 2025 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to ... |
| CVE-2025-32788 | MEDIUM | 4.3 | 0.2% | Apr 22, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPri... |
| CVE-2025-28039 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s... |
| CVE-2025-28038 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s... |
| CVE-2025-28036 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se... |
| CVE-2025-28035 | CRITICAL | 9.8 | 1.1% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set... |
| CVE-2025-28029 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-28027 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-28026 | HIGH | 7.3 | 0.3% | Apr 22, 2025 | TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2c... |
| CVE-2025-34028 | CRITICAL | 10 | 97.2% | Apr 22, 2025 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta... |
| CVE-2025-29339 | HIGH | 7.5 | 0.4% | Apr 22, 2025 | An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session paramete... |
| CVE-2025-27907 | LOW | 2.7 | 0.3% | Apr 22, 2025 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an auth... |
| CVE-2025-3767 | HIGH | 7.2 | 0.3% | Apr 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Bool... |
| CVE-2025-28037 | CRITICAL | 9.8 | 0.9% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman... |
| CVE-2025-28031 | MEDIUM | 6.5 | 0.2% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.... |
| CVE-2025-28030 | HIGH | 8.8 | 0.4% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime paramete... |
| CVE-2025-28024 | CRITICAL | 9.8 | 0.5% | Apr 22, 2025 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi |
| CVE-2025-23251 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by rem... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now