2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58580MEDIUM5.3An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation ...
CVE-2025-58579MEDIUM5.3Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t...
CVE-2025-58578MEDIUM4.3A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r...
CVE-2025-9710MEDIUM6.3The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio...
CVE-2025-9703MEDIUM4.3The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa...
CVE-2025-11321MEDIUM4.3A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi...
CVE-2025-11320MEDIUM6.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up...
CVE-2025-11319MEDIUM6.3A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16...
CVE-2025-50538MEDIUM6.1Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
CVE-2025-29192MEDIUM6.1Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
CVE-2025-11306MEDIUM6.1A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the...
CVE-2025-11304MEDIUM6.3A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown function...
CVE-2025-11291MEDIUM4.3A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts a...
CVE-2025-8917MEDIUM5.8A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and h...
CVE-2025-11289MEDIUM5.4A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted elemen...
CVE-2025-11286MEDIUM4.7A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controlle...
CVE-2025-11282MEDIUM6.1A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Inco...
CVE-2025-11281MEDIUM5A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ o...
CVE-2025-11279MEDIUM5.5A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing ...
CVE-2025-11278MEDIUM4.3A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of...
CVE-2025-11276MEDIUM5.1A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the ...
CVE-2025-11274MEDIUM5.5A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternRe...
CVE-2025-11273MEDIUM6.3A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the f...
CVE-2025-11272MEDIUM5.4A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.R...
CVE-2025-39953MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cgroup: split cgroup_destroy_wq into 3 workqueues ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now