2025 CVE Vulnerabilities
45,330 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0609 | MEDIUM | 4.7 | 0.2% | Oct 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Softwa... |
| CVE-2025-0608 | MEDIUM | 5.5 | 0.1% | Oct 6, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc... |
| CVE-2025-0607 | MEDIUM | 4.3 | 0.2% | Oct 6, 2025 | Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe... |
| CVE-2025-0606 | MEDIUM | 6 | 0.3% | Oct 6, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing... |
| CVE-2025-59731 | MEDIUM | 6.9 | 0.2% | Oct 6, 2025 | When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is... |
| CVE-2025-59730 | MEDIUM | 5.7 | 0.1% | Oct 6, 2025 | When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it... |
| CVE-2025-59729 | MEDIUM | 5.7 | 0.1% | Oct 6, 2025 | When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the du... |
| CVE-2025-9913 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab... |
| CVE-2025-58589 | MEDIUM | 6.5 | 0.3% | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method... |
| CVE-2025-58586 | MEDIUM | 5.3 | 0.3% | Oct 6, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to... |
| CVE-2025-58583 | MEDIUM | 5.3 | 0.3% | Oct 6, 2025 | The application provides access to a login protected H2 database for caching purposes. The username is prefil... |
| CVE-2025-58581 | MEDIUM | 4.3 | 0.3% | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho... |
| CVE-2025-58580 | MEDIUM | 5.3 | 0.3% | Oct 6, 2025 | An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation ... |
| CVE-2025-58579 | MEDIUM | 5.3 | 0.4% | Oct 6, 2025 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t... |
| CVE-2025-58578 | MEDIUM | 4.3 | 0.3% | Oct 6, 2025 | A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r... |
| CVE-2025-9710 | MEDIUM | 6.3 | 0.2% | Oct 6, 2025 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio... |
| CVE-2025-9703 | MEDIUM | 4.3 | 0.2% | Oct 6, 2025 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa... |
| CVE-2025-11321 | MEDIUM | 4.3 | 0.4% | Oct 6, 2025 | A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi... |
| CVE-2025-11320 | MEDIUM | 6.3 | 0.3% | Oct 6, 2025 | A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up... |
| CVE-2025-11319 | MEDIUM | 6.3 | 0.2% | Oct 6, 2025 | A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16... |
| CVE-2025-50538 | MEDIUM | 6.1 | 14.0% | Oct 6, 2025 | Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log. |
| CVE-2025-29192 | MEDIUM | 6.1 | 0.4% | Oct 6, 2025 | Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log. |
| CVE-2025-11306 | MEDIUM | 6.1 | 0.3% | Oct 5, 2025 | A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the... |
| CVE-2025-11304 | MEDIUM | 6.3 | 0.2% | Oct 5, 2025 | A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown function... |
| CVE-2025-11291 | MEDIUM | 4.3 | 0.3% | Oct 5, 2025 | A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now