2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32030 | HIGH | 7.5 | 0.5% | Apr 7, 2025 | Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to ... |
| CVE-2025-31496 | HIGH | 7.5 | 0.4% | Apr 7, 2025 | apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Com... |
| CVE-2025-29087 | HIGH | 7.5 | 0.5% | Apr 7, 2025 | In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the en... |
| CVE-2025-3426 | HIGH | 7.2 | 0.1% | Apr 7, 2025 | We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Spe... |
| CVE-2025-3425 | HIGH | 7.3 | 0.3% | Apr 7, 2025 | The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the expl... |
| CVE-2025-3424 | HIGH | 7.7 | 0.2% | Apr 7, 2025 | The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the expl... |
| CVE-2025-28409 | HIGH | 8.8 | 0.5% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endp... |
| CVE-2025-28407 | HIGH | 8.8 | 0.5% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endp... |
| CVE-2025-28403 | HIGH | 7.2 | 0.5% | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly vali... |
| CVE-2025-30195 | HIGH | 7.5 | 0.7% | Apr 7, 2025 | An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets c... |
| CVE-2025-3353 | HIGH | 7.3 | 0.4% | Apr 7, 2025 | A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. This affect... |
| CVE-2025-3348 | HIGH | 8.8 | 0.4% | Apr 7, 2025 | A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerabili... |
| CVE-2025-21448 | HIGH | 7.5 | 0.2% | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. |
| CVE-2025-21447 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption may occur while processing device IO control call for session control. |
| CVE-2025-21443 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption while processing message content in eAVB. |
| CVE-2025-21442 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption while transmitting packet mapping information with invalid header payload size. |
| CVE-2025-21441 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
| CVE-2025-21440 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
| CVE-2025-21439 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provi... |
| CVE-2025-21438 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption while IOCTL call is invoked from user-space to read board data. |
| CVE-2025-21437 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption while processing memory map or unmap IOCTL operations simultaneously. |
| CVE-2025-21436 | HIGH | 7.8 | 0.1% | Apr 7, 2025 | Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threa... |
| CVE-2025-21435 | HIGH | 7.5 | 0.2% | Apr 7, 2025 | Transient DOS may occur while parsing extended IE in beacon. |
| CVE-2025-21434 | HIGH | 7.5 | 0.2% | Apr 7, 2025 | Transient DOS may occur while parsing EHT operation IE or EHT capability IE. |
| CVE-2025-21430 | HIGH | 7.5 | 0.2% | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now