2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9914HIGH7.5The credentials of the users stored in the system's local database can be used for the log in, making it possible for an...
CVE-2025-9913MEDIUM6.1JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerab...
CVE-2025-58591HIGH7.5A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, mak...
CVE-2025-58590HIGH7.5It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.
CVE-2025-58589MEDIUM6.5When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method...
CVE-2025-58587CRITICAL9.8The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short...
CVE-2025-58586MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-58585HIGH7.5Multiple endpoints with sensitive information do not require authentication, making the application susceptible to infor...
CVE-2025-58584HIGH7.5In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be s...
CVE-2025-58583MEDIUM5.3The application provides access to a login protected H2 database for caching purposes. The username is prefil...
CVE-2025-58582HIGH7.5If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is...
CVE-2025-58581MEDIUM4.3When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho...
CVE-2025-58580MEDIUM5.3An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation ...
CVE-2025-58579MEDIUM5.3Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making t...
CVE-2025-58578MEDIUM4.3A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST r...
CVE-2025-11325HIGH8.8A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionalit...
CVE-2025-11324HIGH8.8A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionali...
CVE-2025-9710MEDIUM6.3The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modificatio...
CVE-2025-9703MEDIUM4.3The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sa...
CVE-2025-57781HIGH8.4The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurel...
CVE-2025-11323HIGH8.8A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/...
CVE-2025-11322LOW3.7A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga....
CVE-2025-11321MEDIUM4.3A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi...
CVE-2025-11320MEDIUM6.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up...
CVE-2025-11319MEDIUM6.3A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now