2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-56382MEDIUM6.1A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4...
CVE-2025-28129MEDIUM5.4Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
CVE-2025-61769MEDIUM6.1Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including...
CVE-2025-61766MEDIUM6.5Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu...
CVE-2025-60969MEDIUM5.7Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00...
CVE-2025-60961MEDIUM6.1Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V...
CVE-2025-0038MEDIUM6.6In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm...
CVE-2025-61765MEDIUM6.4python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab...
CVE-2025-61224MEDIUM6.5Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra...
CVE-2025-61198MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Opt...
CVE-2025-11337MEDIUM5.5A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown...
CVE-2025-11336MEDIUM5.5A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected ...
CVE-2025-11332MEDIUM6.1A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php ...
CVE-2025-0609MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Softwa...
CVE-2025-0608MEDIUM5.5URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc...
CVE-2025-0607MEDIUM4.3Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe...
CVE-2025-0606MEDIUM6Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing...
CVE-2025-59731MEDIUM6.9When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is...
CVE-2025-59730MEDIUM5.7When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it...
CVE-2025-59729MEDIUM5.7When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the du...
CVE-2025-9913MEDIUM6.1JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab...
CVE-2025-58589MEDIUM6.5When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method...
CVE-2025-58586MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-58583MEDIUM5.3The application provides access to a login protected H2 database for caching purposes. The username is prefil...
CVE-2025-58581MEDIUM4.3When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now