2025 CVE Vulnerabilities
45,191 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46326 | HIGH | 7 | 0.1% | Apr 28, 2025 | snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerabl... |
| CVE-2025-3224 | HIGH | 7.8 | 0.2% | Apr 28, 2025 | A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr... |
| CVE-2025-34491 | HIGH | 8.8 | 0.7% | Apr 28, 2025 | GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attac... |
| CVE-2025-31650 | HIGH | 7.5 | 66.9% | Apr 28, 2025 | Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority header... |
| CVE-2025-4032 | HIGH | 8.1 | 3.2% | Apr 28, 2025 | A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as cri... |
| CVE-2025-34489 | HIGH | 7.8 | 0.3% | Apr 28, 2025 | GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escal... |
| CVE-2025-4029 | HIGH | 7.8 | 0.3% | Apr 28, 2025 | A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-23375 | HIGH | 7.8 | 0.1% | Apr 28, 2025 | Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability... |
| CVE-2025-4022 | HIGH | 8.8 | 0.4% | Apr 28, 2025 | A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affe... |
| CVE-2025-4021 | HIGH | 7.5 | 0.3% | Apr 28, 2025 | A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Thi... |
| CVE-2025-4018 | HIGH | 7.5 | 0.7% | Apr 28, 2025 | A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97... |
| CVE-2025-4015 | HIGH | 7.5 | 0.7% | Apr 28, 2025 | A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as cr... |
| CVE-2025-4012 | HIGH | 7.5 | 0.4% | Apr 28, 2025 | A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some ... |
| CVE-2025-42598 | HIGH | 8.4 | 0.2% | Apr 28, 2025 | Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when inst... |
| CVE-2025-32470 | HIGH | 7.5 | 0.5% | Apr 28, 2025 | A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availab... |
| CVE-2025-4007 | HIGH | 8.8 | 0.8% | Apr 28, 2025 | A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vuln... |
| CVE-2025-22235 | HIGH | 7.3 | 0.4% | Apr 28, 2025 | EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been crea... |
| CVE-2025-3993 | HIGH | 8.8 | 0.9% | Apr 28, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown... |
| CVE-2025-3992 | HIGH | 8.8 | 0.9% | Apr 28, 2025 | A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects... |
| CVE-2025-3991 | HIGH | 8.8 | 0.9% | Apr 28, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown... |
| CVE-2025-27937 | HIGH | 7.1 | 0.6% | Apr 28, 2025 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Pa... |
| CVE-2025-3990 | HIGH | 8.8 | 0.9% | Apr 27, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this i... |
| CVE-2025-3989 | HIGH | 8.8 | 0.9% | Apr 27, 2025 | A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is a... |
| CVE-2025-46690 | HIGH | 8.8 | 0.3% | Apr 27, 2025 | Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats r... |
| CVE-2025-3988 | HIGH | 8.8 | 1.1% | Apr 27, 2025 | A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown functio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now