2025 CVE Vulnerabilities
45,199 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32986 | HIGH | 7.5 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint. |
| CVE-2025-32983 | HIGH | 7.5 | 0.4% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace. |
| CVE-2025-32982 | HIGH | 7.5 | 0.3% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module. |
| CVE-2025-32981 | HIGH | 7.1 | 0.2% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File. |
| CVE-2025-28128 | HIGH | 7 | 0.4% | Apr 25, 2025 | An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a craft... |
| CVE-2025-3935 | HIGH | 7.2 | 3.3% | Apr 25, 2025 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web ... |
| CVE-2025-3928 | HIGH | 8.8 | 1.9% | Apr 25, 2025 | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. Accordi... |
| CVE-2025-43862 | HIGH | 7.6 | 0.3% | Apr 25, 2025 | Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify... |
| CVE-2025-43016 | HIGH | 7.5 | 0.3% | Apr 25, 2025 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |
| CVE-2025-3642 | HIGH | 8.8 | 0.8% | Apr 25, 2025 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default... |
| CVE-2025-3641 | HIGH | 8.8 | 0.8% | Apr 25, 2025 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default... |
| CVE-2025-3638 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to pr... |
| CVE-2025-3625 | HIGH | 7.1 | 0.4% | Apr 25, 2025 | A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about s... |
| CVE-2025-32044 | HIGH | 7.5 | 0.3% | Apr 25, 2025 | A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—i... |
| CVE-2025-1565 | HIGH | 7.5 | 0.5% | Apr 25, 2025 | The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 v... |
| CVE-2025-1279 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg... |
| CVE-2025-46617 | HIGH | 7.2 | 0.3% | Apr 25, 2025 | Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification... |
| CVE-2025-2238 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to... |
| CVE-2025-46613 | HIGH | 7.5 | 0.2% | Apr 25, 2025 | OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after... |
| CVE-2025-3511 | HIGH | 7.5 | 1.1% | Apr 25, 2025 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remot... |
| CVE-2025-46546 | HIGH | 8.8 | 0.3% | Apr 25, 2025 | In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This ... |
| CVE-2025-43865 | HIGH | 8.2 | 0.7% | Apr 25, 2025 | React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-re... |
| CVE-2025-43864 | HIGH | 7.5 | 23.6% | Apr 25, 2025 | React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an app... |
| CVE-2025-3606 | HIGH | 8.7 | 0.3% | Apr 25, 2025 | Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing s... |
| CVE-2025-2185 | HIGH | 8.5 | 0.3% | Apr 25, 2025 | ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient se... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now