2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56382 | MEDIUM | 6.1 | 0.2% | Oct 6, 2025 | A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4... |
| CVE-2025-28129 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. |
| CVE-2025-61769 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including... |
| CVE-2025-61766 | MEDIUM | 6.5 | 0.3% | Oct 6, 2025 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu... |
| CVE-2025-60969 | MEDIUM | 5.7 | 0.5% | Oct 6, 2025 | Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00... |
| CVE-2025-60961 | MEDIUM | 6.1 | 0.2% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V... |
| CVE-2025-0038 | MEDIUM | 6.6 | 0.1% | Oct 6, 2025 | In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm... |
| CVE-2025-61765 | MEDIUM | 6.4 | 0.5% | Oct 6, 2025 | python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab... |
| CVE-2025-61224 | MEDIUM | 6.5 | 1.3% | Oct 6, 2025 | Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra... |
| CVE-2025-61198 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Opt... |
| CVE-2025-11337 | MEDIUM | 5.5 | 0.6% | Oct 6, 2025 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown... |
| CVE-2025-11336 | MEDIUM | 5.5 | 0.6% | Oct 6, 2025 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected ... |
| CVE-2025-11332 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php ... |
| CVE-2025-0609 | MEDIUM | 4.7 | 0.2% | Oct 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Softwa... |
| CVE-2025-0608 | MEDIUM | 5.5 | 0.1% | Oct 6, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc... |
| CVE-2025-0607 | MEDIUM | 4.3 | 0.2% | Oct 6, 2025 | Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe... |
| CVE-2025-0606 | MEDIUM | 6 | 0.3% | Oct 6, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing... |
| CVE-2025-59731 | MEDIUM | 6.9 | 0.2% | Oct 6, 2025 | When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is... |
| CVE-2025-59730 | MEDIUM | 5.7 | 0.1% | Oct 6, 2025 | When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it... |
| CVE-2025-59729 | MEDIUM | 5.7 | 0.1% | Oct 6, 2025 | When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the du... |
| CVE-2025-9913 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab... |
| CVE-2025-58589 | MEDIUM | 6.5 | 0.3% | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method... |
| CVE-2025-58586 | MEDIUM | 5.3 | 0.3% | Oct 6, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to... |
| CVE-2025-58583 | MEDIUM | 5.3 | 0.3% | Oct 6, 2025 | The application provides access to a login protected H2 database for caching purposes. The username is prefil... |
| CVE-2025-58581 | MEDIUM | 4.3 | 0.3% | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now