2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33026 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass... |
| CVE-2025-29705 | MEDIUM | 4.3 | 0.3% | Apr 15, 2025 | code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone... |
| CVE-2025-28100 | CRITICAL | 9.8 | 0.5% | Apr 15, 2025 | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the co... |
| CVE-2025-32780 | HIGH | 7.3 | 0.2% | Apr 15, 2025 | BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerab... |
| CVE-2025-32779 | MEDIUM | 6.5 | 1.0% | Apr 15, 2025 | E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,... |
| CVE-2025-32776 | MEDIUM | 5.5 | 0.2% | Apr 15, 2025 | OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu... |
| CVE-2025-29817 | MEDIUM | 5.7 | 0.7% | Apr 15, 2025 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. |
| CVE-2025-32911 | CRITICAL | 9 | 0.8% | Apr 15, 2025 | A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function... |
| CVE-2025-28198 | MEDIUM | 5.9 | 0.2% | Apr 15, 2025 | A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the or... |
| CVE-2025-24949 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | In JotUrl 2.0, is possible to bypass security requirements during the password change process. |
| CVE-2025-24948 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insec... |
| CVE-2025-3523 | MEDIUM | 6.4 | 0.3% | Apr 15, 2025 | When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t... |
| CVE-2025-3522 | MEDIUM | 6.3 | 0.2% | Apr 15, 2025 | Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally.... |
| CVE-2025-32949 | MEDIUM | 6.5 | 0.5% | Apr 15, 2025 | This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when ex... |
| CVE-2025-32948 | HIGH | 7.5 | 0.5% | Apr 15, 2025 | The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send request... |
| CVE-2025-32947 | HIGH | 7.5 | 0.6% | Apr 15, 2025 | This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite lo... |
| CVE-2025-2830 | MEDIUM | 6.3 | 0.3% | Apr 15, 2025 | By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu... |
| CVE-2025-29281 | HIGH | 8.8 | 0.6% | Apr 15, 2025 | In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component... |
| CVE-2025-28145 | MEDIUM | 6.5 | 8.0% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerab... |
| CVE-2025-28144 | MEDIUM | 6.5 | 3.8% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerabili... |
| CVE-2025-28143 | MEDIUM | 6.5 | 7.7% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab... |
| CVE-2025-28142 | MEDIUM | 6.5 | 8.0% | Apr 15, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab... |
| CVE-2025-27980 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=. |
| CVE-2025-29280 | MEDIUM | 4.8 | 0.2% | Apr 15, 2025 | Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system ... |
| CVE-2025-28137 | CRITICAL | 9.8 | 10.3% | Apr 15, 2025 | The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now