Vulnerability Report - April 2025

Vulnerability Report - April 2025

May 1, 2025

 #VulnerabilityReport#Report

All vulnerability reports

Introduction

This vulnerability report has been generated using data aggregated on Vulnerability-Lookup, with contributions from the platform’s community.

It highlights the most frequently mentioned vulnerability for April 2025, based on sightings collected from various sources, including MISP, Exploit-DB, Bluesky, Mastodon, GitHub Gists, The Shadowserver Foundation, Nuclei, and more. For further details, please visit this page.

The final section focuses on exploitations observed through The Shadowserver Foundation’s honeypot network.

Top 10 vulnerabilities of the month

VulnerabilityVendorProductCountSeverity
CVE-2025-22457IvantiConnect Secure1889
CVE-2025-32433erlangotp11910
CVE-2025-31324SAPSAP NetWeaver10110
CVE-2025-31161CrushFTPCrushFTP1089.8
CVE-2025-29824MicrosoftWindows 10 Version 1809857.8
CVE-2025-24054MicrosoftWindows 10 Version 1809796.5
CVE-2025-30406GladinetCentreStack649
CVE-2025-24200AppleiPadOS616.1
CVE-2017-18368ZyXELp660hn-t1a_v1, p660hn-t1a_v2, 5200w-t609.8
CVE-2015-2051dlinkdir-645608.8

A scanner is available for CVE-2025-31324 (SAP):

You can create a notification for this SAP product to get alerts about new activity.

CVE-2017-18368 and CVE-2015-2051 are continuously exploited, with a recent increase in activity.

Evolution per week

Week 14

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-22457IvantiConnect Secure1009.0
CVE-2025-31161CrushFTPCrushFTP469.8
CVE-2025-30065Apache Software FoundationApache Parquet Java2710
CVE-2025-24813Apache Software FoundationApache Tomcat269.8
CVE-2025-1268Canon Inc.Generic Plus PCL6 Printer Driver259.4
CVE-2024-20439CiscoCisco Smart License Utility219.8
CVE-2025-1974kubernetesingress-nginx209.8
CVE-2025-26633MicrosoftWindows 10 Version 1809197
CVE-2025-24201AppleiOS and iPadOS157.1

Week 15

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-29824MicrosoftWindows 10 Version 1809597.8
CVE-2025-22457IvantiConnect Secure559.0
CVE-2025-24200AppleiPadOS466.1
CVE-2024-53197LinuxLinux427.8
CVE-2025-31161CrushFTPCrushFTP389.8
CVE-2024-53150LinuxLinux367.8
CVE-2024-48887FortinetFortiSwitch319.8
CVE-2024-0132NVIDIAContainer Toolkit249
CVE-2025-0108Palo Alto NetworksCloud NGFW188.8

Insights from contributors

Week 16

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-32433erlangotp7010
CVE-2025-24054MicrosoftWindows 10 Version 1809587.8
CVE-2025-31200ApplevisionOS497.5
CVE-2025-30406GladinetCentreStack449
CVE-2025-31201ApplevisionOS426.8
CVE-2025-24859Apache Software FoundationApache Roller322.1
CVE-2021-20035SonicWallSMA100266.5
CVE-2025-29824MicrosoftWindows 10 Version 1809247.8
CVE-2025-22457IvantiConnect Secure239.0
CVE-2024-56406perlperl188.6

Insights from contributors

Week 17

Ranking

VulnerabilityVendorProductCountSeverity
CVE-2025-32433erlangotp4210
CVE-2025-31324SAPSAP NetWeaver4210
CVE-2025-34028CommvaultCommand Center Innovation Release3910
CVE-2025-0282IvantiConnect Secure249
CVE-2025-32434pytorchpytorch199.3
CVE-2025-24054MicrosoftWindows 10 Version 1809196.5
CVE-2021-42013Apache Software FoundationApache HTTP Server169.8
CVE-2015-2051dlinkdir-645148.8
CVE-2017-18368ZyXELp660hn-t1a_v1, p660hn-t1a_v2, 5200w-t149.8
CVE-2025-1731ZyxelUSG FLEX H series uOS firmware137.8

Insights from contributors

CVEs with appearances from week 14 to 17

Persistent ones (appear in at least 2 weeks):

  • CVE-2025-22457 – Week 14, 15, 16, 17
  • CVE-2025-31161 – Week 14, 15, 17
  • CVE-2025-29824 – Week 15, 16
  • CVE-2025-24054 – Week 16, 17

Appear only once

Week 14 only:

  • CVE-2025-30065, CVE-2025-24813, CVE-2025-1268, CVE-2024-20439, CVE-2025-1974

Week 15 only:

  • CVE-2025-24200, CVE-2024-53197, CVE-2024-53150

Week 16 only:

  • CVE-2025-32433, CVE-2025-31200 Week 17 only:

  • CVE-2025-31324, CVE-2025-0282, CVE-2025-1731

Continuous exploitation

The sightings used for this analysis were mainly collected through The Shadowserver Foundation’s honeypot network.

VulnerabilityCount
CVE-2015-205130
CVE-2019-165330
CVE-2019-1278030
CVE-2017-1836830
CVE-2022-2613430
CVE-2023-3864630
CVE-2021-4201330
CVE-2016-627730
CVE-2018-1056230
CVE-2025-010830
CVE-2016-1037230
CVE-2021-4422830
CVE-2017-984130
CVE-2017-1721530

This table highlights vulnerabilities that are consistently and recently exploited at a high rate. Often found at network edges, such as routers, VPNs, and similar devices.

Thank you

Thank you to all the contributors and our diverse sources!

If you want to contribute to the next report, you can create your account.

Feedback and Support

If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!
https://github.com/vulnerability-lookup/vulnerability-lookup/issues/