2025 CVE Vulnerabilities
45,295 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3962 | MEDIUM | 4.1 | 0.3% | Apr 27, 2025 | A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects... |
| CVE-2025-3961 | MEDIUM | 4.1 | 0.3% | Apr 27, 2025 | A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unkno... |
| CVE-2025-3960 | CRITICAL | 9.8 | 0.5% | Apr 27, 2025 | A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issu... |
| CVE-2025-3959 | MEDIUM | 5.3 | 0.3% | Apr 27, 2025 | A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by thi... |
| CVE-2025-3958 | MEDIUM | 4.1 | 0.3% | Apr 27, 2025 | A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is a... |
| CVE-2025-3957 | CRITICAL | 9.8 | 0.4% | Apr 27, 2025 | A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown pro... |
| CVE-2025-3956 | CRITICAL | 9.8 | 0.4% | Apr 27, 2025 | A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the... |
| CVE-2025-46580 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt th... |
| CVE-2025-46579 | HIGH | 7.8 | 0.3% | Apr 27, 2025 | There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through th... |
| CVE-2025-46578 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit t... |
| CVE-2025-46577 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract databa... |
| CVE-2025-46576 | MEDIUM | 6.5 | 0.2% | Apr 27, 2025 | There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipu... |
| CVE-2025-46575 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ... |
| CVE-2025-46574 | MEDIUM | 5.3 | 0.2% | Apr 27, 2025 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ... |
| CVE-2025-46675 | MEDIUM | 4.2 | 0.3% | Apr 27, 2025 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. |
| CVE-2025-46674 | CRITICAL | 9.9 | 0.5% | Apr 27, 2025 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), p... |
| CVE-2025-46673 | CRITICAL | 9.9 | 0.4% | Apr 27, 2025 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a b... |
| CVE-2025-46672 | HIGH | 8.8 | 0.4% | Apr 27, 2025 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft h... |
| CVE-2025-3955 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This ... |
| CVE-2025-46656 | LOW | 3.3 | 0.2% | Apr 26, 2025 | python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1>... |
| CVE-2025-3954 | MEDIUM | 6.3 | 0.5% | Apr 26, 2025 | A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some... |
| CVE-2025-46655 | MEDIUM | 4.9 | 0.2% | Apr 26, 2025 | CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScri... |
| CVE-2025-46654 | MEDIUM | 4.9 | 0.2% | Apr 26, 2025 | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be... |
| CVE-2025-46653 | LOW | 3.1 | 0.4% | Apr 26, 2025 | Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for un... |
| CVE-2025-46652 | MEDIUM | 6.1 | 0.3% | Apr 26, 2025 | In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archiv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now