2025 CVE Vulnerabilities
45,212 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2440 | MEDIUM | 4.2 | 0.2% | Apr 9, 2025 | CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized acce... |
| CVE-2025-27722 | MEDIUM | 5.9 | 0.3% | Apr 9, 2025 | Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-... |
| CVE-2025-25213 | MEDIUM | 6.5 | 0.3% | Apr 9, 2025 | Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views... |
| CVE-2025-25056 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | Cross-site request forgery vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views a malicious page ... |
| CVE-2025-23407 | MEDIUM | 4.3 | 0.3% | Apr 9, 2025 | Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac serie... |
| CVE-2025-20952 | MEDIUM | 5.5 | 0.1% | Apr 9, 2025 | Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files ... |
| CVE-2025-3442 | MEDIUM | 4.4 | 0.1% | Apr 9, 2025 | This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart Hub due to storage of Wi-Fi credentials in plain text withi... |
| CVE-2025-3100 | MEDIUM | 5.4 | 0.2% | Apr 9, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2025-32464 | MEDIUM | 6.8 | 0.7% | Apr 9, 2025 | HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow becau... |
| CVE-2025-29988 | MEDIUM | 6.7 | 0.1% | Apr 9, 2025 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local ac... |
| CVE-2025-25013 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as AP... |
| CVE-2025-27191 | MEDIUM | 5.3 | 0.4% | Apr 8, 2025 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Ac... |
| CVE-2025-27190 | MEDIUM | 5.3 | 0.4% | Apr 8, 2025 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Ac... |
| CVE-2025-27189 | MEDIUM | 4.3 | 0.9% | Apr 8, 2025 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site R... |
| CVE-2025-27188 | MEDIUM | 4.3 | 0.4% | Apr 8, 2025 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Au... |
| CVE-2025-30294 | MEDIUM | 6.8 | 10.4% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-30293 | MEDIUM | 6.8 | 0.6% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that... |
| CVE-2025-30292 | MEDIUM | 6.1 | 11.1% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerab... |
| CVE-2025-30291 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that coul... |
| CVE-2025-30309 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosu... |
| CVE-2025-30308 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosu... |
| CVE-2025-30307 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosu... |
| CVE-2025-30306 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosu... |
| CVE-2025-30305 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosu... |
| CVE-2025-30303 | MEDIUM | 5.5 | 0.2% | Apr 8, 2025 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now