2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58580 | MEDIUM | 5.3 | 0.3% | Oct 6, 2025 | An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation ... |
| CVE-2025-58579 | MEDIUM | 5.3 | 0.4% | Oct 6, 2025 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t... |
| CVE-2025-58578 | MEDIUM | 4.3 | 0.3% | Oct 6, 2025 | A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r... |
| CVE-2025-9710 | MEDIUM | 6.3 | 0.2% | Oct 6, 2025 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio... |
| CVE-2025-9703 | MEDIUM | 4.3 | 0.2% | Oct 6, 2025 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa... |
| CVE-2025-11321 | MEDIUM | 4.3 | 0.3% | Oct 6, 2025 | A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi... |
| CVE-2025-11320 | MEDIUM | 6.3 | 0.3% | Oct 6, 2025 | A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up... |
| CVE-2025-11319 | MEDIUM | 6.3 | 0.2% | Oct 6, 2025 | A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16... |
| CVE-2025-50538 | MEDIUM | 6.1 | 12.9% | Oct 6, 2025 | Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log. |
| CVE-2025-29192 | MEDIUM | 6.1 | 0.4% | Oct 6, 2025 | Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log. |
| CVE-2025-11306 | MEDIUM | 6.1 | 0.3% | Oct 5, 2025 | A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the... |
| CVE-2025-11304 | MEDIUM | 6.3 | 0.2% | Oct 5, 2025 | A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown function... |
| CVE-2025-11291 | MEDIUM | 4.3 | 0.3% | Oct 5, 2025 | A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts a... |
| CVE-2025-8917 | MEDIUM | 5.8 | 0.3% | Oct 5, 2025 | A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and h... |
| CVE-2025-11289 | MEDIUM | 5.4 | 0.3% | Oct 5, 2025 | A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted elemen... |
| CVE-2025-11286 | MEDIUM | 4.7 | 0.3% | Oct 5, 2025 | A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controlle... |
| CVE-2025-11282 | MEDIUM | 6.1 | 0.4% | Oct 5, 2025 | A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Inco... |
| CVE-2025-11281 | MEDIUM | 5 | 0.3% | Oct 5, 2025 | A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ o... |
| CVE-2025-11279 | MEDIUM | 5.5 | 0.2% | Oct 5, 2025 | A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing ... |
| CVE-2025-11278 | MEDIUM | 4.3 | 0.3% | Oct 5, 2025 | A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of... |
| CVE-2025-11276 | MEDIUM | 5.1 | 0.2% | Oct 5, 2025 | A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the ... |
| CVE-2025-11274 | MEDIUM | 5.5 | 0.2% | Oct 5, 2025 | A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternRe... |
| CVE-2025-11273 | MEDIUM | 6.3 | 0.3% | Oct 4, 2025 | A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the f... |
| CVE-2025-11272 | MEDIUM | 5.4 | 0.3% | Oct 4, 2025 | A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.R... |
| CVE-2025-39953 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: cgroup: split cgroup_destroy_wq into 3 workqueues ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now