2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2222 | HIGH | 8.2 | 0.3% | Apr 9, 2025 | CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information... |
| CVE-2025-29870 | HIGH | 7.5 | 0.5% | Apr 9, 2025 | Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a... |
| CVE-2025-27934 | HIGH | 7.5 | 0.5% | Apr 9, 2025 | Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-W... |
| CVE-2025-25053 | HIGH | 8.8 | 0.9% | Apr 9, 2025 | OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exp... |
| CVE-2025-30290 | HIGH | 8.7 | 12.4% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restr... |
| CVE-2025-30289 | HIGH | 8.2 | 5.0% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements ... |
| CVE-2025-30288 | HIGH | 8.2 | 0.3% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-30287 | HIGH | 8.2 | 2.7% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that c... |
| CVE-2025-30286 | HIGH | 8.4 | 2.2% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements ... |
| CVE-2025-30285 | HIGH | 8.4 | 18.2% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-30284 | HIGH | 8.4 | 1.6% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2025-30304 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could res... |
| CVE-2025-30299 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that cou... |
| CVE-2025-30298 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co... |
| CVE-2025-30297 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could res... |
| CVE-2025-30296 | HIGH | 7.8 | 0.2% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi... |
| CVE-2025-30295 | HIGH | 7.8 | 0.3% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that cou... |
| CVE-2025-32035 | HIGH | 7.5 | 0.2% | Apr 8, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9... |
| CVE-2025-29824 | HIGH | 7.8 | 18.0% | Apr 8, 2025 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-29823 | HIGH | 7.8 | 0.6% | Apr 8, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-29822 | HIGH | 7.8 | 0.7% | Apr 8, 2025 | Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security fe... |
| CVE-2025-29820 | HIGH | 7.8 | 0.7% | Apr 8, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-29816 | HIGH | 7.5 | 0.4% | Apr 8, 2025 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a n... |
| CVE-2025-29812 | HIGH | 7.8 | 0.7% | Apr 8, 2025 | Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. |
| CVE-2025-29811 | HIGH | 7.8 | 0.5% | Apr 8, 2025 | Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now