2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46657 | MEDIUM | 6.1 | 0.3% | Apr 27, 2025 | Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI. |
| CVE-2025-3975 | MEDIUM | 6.9 | 0.6% | Apr 27, 2025 | A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affec... |
| CVE-2025-3970 | MEDIUM | 5.4 | 0.3% | Apr 27, 2025 | A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of ... |
| CVE-2025-3967 | MEDIUM | 5.4 | 0.4% | Apr 27, 2025 | A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part ... |
| CVE-2025-3966 | MEDIUM | 5.3 | 0.4% | Apr 27, 2025 | A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unkn... |
| CVE-2025-3965 | MEDIUM | 5.4 | 0.3% | Apr 27, 2025 | A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability... |
| CVE-2025-3964 | MEDIUM | 5.3 | 0.3% | Apr 27, 2025 | A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an... |
| CVE-2025-3962 | MEDIUM | 4.1 | 0.3% | Apr 27, 2025 | A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects... |
| CVE-2025-3961 | MEDIUM | 4.1 | 0.3% | Apr 27, 2025 | A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unkno... |
| CVE-2025-3959 | MEDIUM | 5.3 | 0.3% | Apr 27, 2025 | A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by thi... |
| CVE-2025-3958 | MEDIUM | 4.1 | 0.3% | Apr 27, 2025 | A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is a... |
| CVE-2025-46576 | MEDIUM | 6.5 | 0.2% | Apr 27, 2025 | There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipu... |
| CVE-2025-46574 | MEDIUM | 5.3 | 0.2% | Apr 27, 2025 | There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ... |
| CVE-2025-46675 | MEDIUM | 4.2 | 0.3% | Apr 27, 2025 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. |
| CVE-2025-3954 | MEDIUM | 6.3 | 0.5% | Apr 26, 2025 | A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some... |
| CVE-2025-46655 | MEDIUM | 4.9 | 0.2% | Apr 26, 2025 | CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScri... |
| CVE-2025-46654 | MEDIUM | 4.9 | 0.2% | Apr 26, 2025 | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be... |
| CVE-2025-46652 | MEDIUM | 6.1 | 0.3% | Apr 26, 2025 | In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archiv... |
| CVE-2025-46646 | MEDIUM | 4.5 | 0.2% | Apr 26, 2025 | In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issu... |
| CVE-2025-2850 | MEDIUM | 5.1 | 0.2% | Apr 26, 2025 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750... |
| CVE-2025-2811 | MEDIUM | 6.9 | 0.3% | Apr 26, 2025 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750... |
| CVE-2025-3915 | MEDIUM | 4.3 | 0.3% | Apr 26, 2025 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili... |
| CVE-2025-1458 | MEDIUM | 5.4 | 0.2% | Apr 26, 2025 | The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is v... |
| CVE-2025-32984 | MEDIUM | 6.1 | 0.2% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter. |
| CVE-2025-32979 | MEDIUM | 6.5 | 0.3% | Apr 25, 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now