2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-46657MEDIUM6.1Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.
CVE-2025-3975MEDIUM6.9A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affec...
CVE-2025-3970MEDIUM5.4A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of ...
CVE-2025-3967MEDIUM5.4A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part ...
CVE-2025-3966MEDIUM5.3A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unkn...
CVE-2025-3965MEDIUM5.4A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability...
CVE-2025-3964MEDIUM5.3A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an...
CVE-2025-3962MEDIUM4.1A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects...
CVE-2025-3961MEDIUM4.1A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unkno...
CVE-2025-3959MEDIUM5.3A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by thi...
CVE-2025-3958MEDIUM4.1A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is a...
CVE-2025-46576MEDIUM6.5There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipu...
CVE-2025-46574MEDIUM5.3There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages ...
CVE-2025-46675MEDIUM4.2In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.
CVE-2025-3954MEDIUM6.3A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some...
CVE-2025-46655MEDIUM4.9CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScri...
CVE-2025-46654MEDIUM4.9CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be...
CVE-2025-46652MEDIUM6.1In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archiv...
CVE-2025-46646MEDIUM4.5In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issu...
CVE-2025-2850MEDIUM5.1A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750...
CVE-2025-2811MEDIUM6.9A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750...
CVE-2025-3915MEDIUM4.3The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili...
CVE-2025-1458MEDIUM5.4The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is v...
CVE-2025-32984MEDIUM6.1NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.
CVE-2025-32979MEDIUM6.5NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now