April 2025 Patch Tuesday: One Zero-Day and 11 Critical Vulnerabilities Among 121 CVEs

Microsoft has addressed 121 vulnerabilities in its April 2025 security update release. This month’s patches include fixes for one actively exploited zero-day vulnerability and 11 Critical vulnerabilit …
Read more

Published Date:
Apr 25, 2025 (1 day, 4 hours ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-29824

CVE-2025-29791

CVE-2025-27752

CVE-2025-27749

CVE-2025-27748

CVE-2025-27745

CVE-2025-27738

CVE-2025-27491

CVE-2025-27482

CVE-2025-27480

CVE-2025-26686

CVE-2025-26670

CVE-2025-26663

CVE-2025-26647

CVE-2025-21197

Read More

CVE ID : CVE-2024-53636

Published : April 26, 2025, 3:15 p.m. | 3 hours, 47 minutes ago

Description : An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

Severity: 6.4 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Read More

CVE ID : CVE-2025-46646

Published : April 26, 2025, 3:15 p.m. | 3 hours, 47 minutes ago

Description : In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

Severity: 4.5 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Read More

CVE ID : CVE-2025-46652

Published : April 26, 2025, 6:15 p.m. | 48 minutes ago

Description : In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not propagated to the extracted files.

Severity: 6.1 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Read More