2025 CVE Vulnerabilities

45,194 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-3987HIGH8.8A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unk...
CVE-2025-3986HIGH7.5A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown c...
CVE-2025-46688HIGH8.4quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer...
CVE-2025-46687HIGH7.8quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overfl...
CVE-2025-3984HIGH7.5A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveSer...
CVE-2025-3983HIGH7.2A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this...
CVE-2025-3982HIGH8.8A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvS...
CVE-2025-3978HIGH7.5A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unkn...
CVE-2025-3968HIGH8.8A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vul...
CVE-2025-3886HIGH8.1An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition ...
CVE-2025-46580HIGH7.5There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt th...
CVE-2025-46579HIGH7.8There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through th...
CVE-2025-46578HIGH7.5There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit t...
CVE-2025-46577HIGH7.5There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract databa...
CVE-2025-46575HIGH7.5There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ...
CVE-2025-46672HIGH8.8NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft h...
CVE-2025-3955HIGH7.5A vulnerability, which was classified as critical, was found in codeprojects Patient Record Management System 1.0. This ...
CVE-2025-2101HIGH8.1The Edumall theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.4 via th...
CVE-2025-2851HIGH8.6A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shad...
CVE-2025-3914HIGH8.8The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val...
CVE-2025-3906HIGH8.8The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-3491HIGH7.2The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i...
CVE-2025-2105HIGH8.1The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8....
CVE-2025-2801HIGH7.3The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerab...
CVE-2025-46333HIGH7.3z2d is a pure Zig 2D graphics library. Versions of z2d after `0.5.1` and up to and including `0.6.0`, when writing from ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now