2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3857 | HIGH | 8.7 | 0.5% | Apr 21, 2025 | When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check t... |
| CVE-2025-32793 | MEDIUM | 4 | 0.1% | Apr 21, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1... |
| CVE-2025-32431 | CRITICAL | 9.1 | 0.8% | Apr 21, 2025 | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-... |
| CVE-2025-28367 | MEDIUM | 6.5 | 2.1% | Apr 21, 2025 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A... |
| CVE-2025-2517 | LOW | 2.3 | 0.4% | Apr 21, 2025 | Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. |
| CVE-2025-2298 | HIGH | 8.4 | 0.3% | Apr 21, 2025 | An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the... |
| CVE-2025-29660 | CRITICAL | 9.8 | 1.2% | Apr 21, 2025 | A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789.... |
| CVE-2025-29659 | CRITICAL | 9.8 | 1.3% | Apr 21, 2025 | Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" bi... |
| CVE-2025-29287 | CRITICAL | 9.8 | 0.7% | Apr 21, 2025 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary cod... |
| CVE-2025-28121 | MEDIUM | 6.1 | 0.7% | Apr 21, 2025 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p... |
| CVE-2025-43916 | LOW | 3.4 | 0.2% | Apr 21, 2025 | Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use... |
| CVE-2025-32408 | LOW | 2.5 | 0.1% | Apr 21, 2025 | In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled. |
| CVE-2025-3840 | LOW | 2.1 | 0.2% | Apr 21, 2025 | An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer co... |
| CVE-2025-3838 | MEDIUM | 6.1 | 0.1% | Apr 21, 2025 | An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for inst... |
| CVE-2025-3837 | MEDIUM | 6.1 | 0.3% | Apr 21, 2025 | An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is d... |
| CVE-2025-25228 | LOW | 3.8 | 0.2% | Apr 21, 2025 | A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execu... |
| CVE-2025-0632 | CRITICAL | 9.2 | 0.7% | Apr 21, 2025 | Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attack... |
| CVE-2025-43973 | CRITICAL | 9.8 | 0.5% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds ... |
| CVE-2025-43972 | HIGH | 7.5 | 0.5% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec pars... |
| CVE-2025-43971 | HIGH | 7.5 | 0.5% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value... |
| CVE-2025-43970 | MEDIUM | 5.3 | 0.4% | Apr 21, 2025 | An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by... |
| CVE-2025-43967 | HIGH | 7.5 | 0.4% | Apr 21, 2025 | libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a gri... |
| CVE-2025-43966 | HIGH | 7.5 | 0.3% | Apr 21, 2025 | libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc. |
| CVE-2025-43964 | CRITICAL | 9.8 | 0.3% | Apr 21, 2025 | In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum... |
| CVE-2025-43963 | CRITICAL | 9.1 | 0.4% | Apr 21, 2025 | In LibRaw before 0.21.4, phase_one_correct in decoders/load_mfbacks.cpp allows out-of-buffer access because split_col an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now