2025 CVE Vulnerabilities

45,330 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0609MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Softwa...
CVE-2025-0608MEDIUM5.5URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forc...
CVE-2025-0607MEDIUM4.3Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe...
CVE-2025-0606MEDIUM6Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing...
CVE-2025-59731MEDIUM6.9When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is...
CVE-2025-59730MEDIUM5.7When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it...
CVE-2025-59729MEDIUM5.7When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the du...
CVE-2025-9913MEDIUM6.1JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab...
CVE-2025-58589MEDIUM6.5When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method...
CVE-2025-58586MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-58583MEDIUM5.3The application provides access to a login protected H2 database for caching purposes. The username is prefil...
CVE-2025-58581MEDIUM4.3When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho...
CVE-2025-58580MEDIUM5.3An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation ...
CVE-2025-58579MEDIUM5.3Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t...
CVE-2025-58578MEDIUM4.3A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r...
CVE-2025-9710MEDIUM6.3The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio...
CVE-2025-9703MEDIUM4.3The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa...
CVE-2025-11321MEDIUM4.3A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi...
CVE-2025-11320MEDIUM6.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up...
CVE-2025-11319MEDIUM6.3A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16...
CVE-2025-50538MEDIUM6.1Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
CVE-2025-29192MEDIUM6.1Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
CVE-2025-11306MEDIUM6.1A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the...
CVE-2025-11304MEDIUM6.3A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown function...
CVE-2025-11291MEDIUM4.3A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now