2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3962MEDIUM4.1A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects...
CVE-2025-3961MEDIUM4.1A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unkno...
CVE-2025-3960CRITICAL9.8A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issu...
CVE-2025-3959MEDIUM5.3A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by thi...
CVE-2025-3958MEDIUM4.1A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is a...
CVE-2025-3957CRITICAL9.8A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown pro...
CVE-2025-3956CRITICAL9.8A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the...
CVE-2025-46580HIGH7.5There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt th...
CVE-2025-46579HIGH7.8There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through th...
CVE-2025-46578HIGH7.5There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit t...
CVE-2025-46577HIGH7.5There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract databa...
CVE-2025-46576MEDIUM6.5There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipu...
CVE-2025-46575HIGH7.5There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ...
CVE-2025-46574MEDIUM5.3There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ...
CVE-2025-46675MEDIUM4.2In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
CVE-2025-46674CRITICAL9.9NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), p...
CVE-2025-46673CRITICAL9.9NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a b...
CVE-2025-46672HIGH8.8NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft h...
CVE-2025-3955HIGH7.5A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This ...
CVE-2025-46656LOW3.3python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>...
CVE-2025-3954MEDIUM6.3A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some...
CVE-2025-46655MEDIUM4.9CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScri...
CVE-2025-46654MEDIUM4.9CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be...
CVE-2025-46653LOW3.1Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un...
CVE-2025-46652MEDIUM6.1In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archiv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now