2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26748HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue ...
CVE-2025-26746HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced C...
CVE-2025-26740MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware Spa...
CVE-2025-26730HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator wi...
CVE-2025-25276MEDIUM6.5An unauthenticated attacker can hijack other users' devices and potentially control them.
CVE-2025-24850MEDIUM6.9An attacker can export other users' plant information.
CVE-2025-24315MEDIUM6.9Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
CVE-2025-24297CRITICAL9.8Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces o...
CVE-2025-22269MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC R...
CVE-2025-22268MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncann...
CVE-2025-22263HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Ga...
CVE-2025-32778CRITICAL9.3Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screens...
CVE-2025-32021HIGH7.5Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing componen...
CVE-2025-31949MEDIUM5.3An authenticated attacker can obtain any plant name by knowing the plant ID.
CVE-2025-31941MEDIUM6.9An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
CVE-2025-31933MEDIUM6.9An unauthenticated attacker can check the existence of usernames in the system by querying an API.
CVE-2025-31499HIGH8.8Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFm...
CVE-2025-31357MEDIUM6.9An unauthenticated attacker can obtain a user's plant list by knowing the username.
CVE-2025-30740MEDIUM6.5Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-30737MEDIUM5.7Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The support...
CVE-2025-30736HIGH7.4Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, ...
CVE-2025-30735HIGH8.1Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page a...
CVE-2025-30733MEDIUM6.5Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-...
CVE-2025-30732MEDIUM6.1Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported ...
CVE-2025-30731LOW3.6Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration)....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now