2025 CVE Vulnerabilities
45,194 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3987 | HIGH | 8.8 | 8.3% | Apr 27, 2025 | A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unk... |
| CVE-2025-3986 | HIGH | 7.5 | 0.5% | Apr 27, 2025 | A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown c... |
| CVE-2025-46688 | HIGH | 8.4 | 0.3% | Apr 27, 2025 | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer... |
| CVE-2025-46687 | HIGH | 7.8 | 0.2% | Apr 27, 2025 | quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overfl... |
| CVE-2025-3984 | HIGH | 7.5 | 0.4% | Apr 27, 2025 | A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveSer... |
| CVE-2025-3983 | HIGH | 7.2 | 16.6% | Apr 27, 2025 | A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this... |
| CVE-2025-3982 | HIGH | 8.8 | 0.5% | Apr 27, 2025 | A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvS... |
| CVE-2025-3978 | HIGH | 7.5 | 0.4% | Apr 27, 2025 | A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unkn... |
| CVE-2025-3968 | HIGH | 8.8 | 0.4% | Apr 27, 2025 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vul... |
| CVE-2025-3886 | HIGH | 8.1 | 0.2% | Apr 27, 2025 | An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition ... |
| CVE-2025-46580 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt th... |
| CVE-2025-46579 | HIGH | 7.8 | 0.3% | Apr 27, 2025 | There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through th... |
| CVE-2025-46578 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit t... |
| CVE-2025-46577 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract databa... |
| CVE-2025-46575 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ... |
| CVE-2025-46672 | HIGH | 8.8 | 0.4% | Apr 27, 2025 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft h... |
| CVE-2025-3955 | HIGH | 7.5 | 0.3% | Apr 27, 2025 | A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This ... |
| CVE-2025-2101 | HIGH | 8.1 | 0.7% | Apr 26, 2025 | The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via th... |
| CVE-2025-2851 | HIGH | 8.6 | 0.4% | Apr 26, 2025 | A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shad... |
| CVE-2025-3914 | HIGH | 8.8 | 11.4% | Apr 26, 2025 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val... |
| CVE-2025-3906 | HIGH | 8.8 | 0.4% | Apr 26, 2025 | The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2025-3491 | HIGH | 7.2 | 0.6% | Apr 26, 2025 | The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i... |
| CVE-2025-2105 | HIGH | 8.1 | 0.6% | Apr 26, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.... |
| CVE-2025-2801 | HIGH | 7.3 | 0.4% | Apr 26, 2025 | The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerab... |
| CVE-2025-46333 | HIGH | 7.3 | 0.1% | Apr 25, 2025 | z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now