Archive // 2025-04

April 2025

Everything the feeds carried with a date in April 2025: still live, or dropped out of the rolling window since. Changes to a CVE's severity, score or exploited status are listed under it.

CVE 07 Apr 2025
CVE-2025-3248 Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP…
Critical 9.8Exploitedfirst seen 04 Oct 2026live