2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1277 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. ... |
| CVE-2025-1276 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vuln... |
| CVE-2025-1275 | HIGH | 7.8 | 0.3% | Apr 15, 2025 | A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overf... |
| CVE-2025-1274 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma... |
| CVE-2025-1273 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vuln... |
| CVE-2025-32445 | CRITICAL | 9.9 | 0.7% | Apr 15, 2025 | Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify Eve... |
| CVE-2025-32439 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track chang... |
| CVE-2025-32438 | HIGH | 8.8 | 0.2% | Apr 15, 2025 | make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS use... |
| CVE-2025-32012 | HIGH | 7.5 | 0.6% | Apr 15, 2025 | Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint ... |
| CVE-2025-31497 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI f... |
| CVE-2025-30206 | CRITICAL | 9.8 | 0.7% | Apr 15, 2025 | Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service co... |
| CVE-2025-2567 | CRITICAL | 9.8 | 0.4% | Apr 15, 2025 | An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling... |
| CVE-2025-1292 | MEDIUM | 6.7 | 0.2% | Apr 15, 2025 | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacke... |
| CVE-2025-1122 | MEDIUM | 6.7 | 0.2% | Apr 15, 2025 | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker wi... |
| CVE-2025-29213 | MEDIUM | 5.5 | 0.3% | Apr 15, 2025 | A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute a... |
| CVE-2025-28399 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of... |
| CVE-2025-27791 | HIGH | 8.3 | 0.4% | Apr 15, 2025 | Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4... |
| CVE-2025-25456 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2. |
| CVE-2025-24358 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior ... |
| CVE-2025-22903 | MEDIUM | 4.6 | 0.2% | Apr 15, 2025 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function ... |
| CVE-2025-22900 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the s... |
| CVE-2025-3618 | MEDIUM | 5.5 | 1.4% | Apr 15, 2025 | A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify... |
| CVE-2025-3617 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files a... |
| CVE-2025-33028 | MEDIUM | 6.1 | 0.5% | Apr 15, 2025 | In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. ... |
| CVE-2025-33027 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now