2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26748 | HIGH | 8.1 | 0.3% | Apr 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue ... |
| CVE-2025-26746 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced C... |
| CVE-2025-26740 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware Spa... |
| CVE-2025-26730 | HIGH | 7.5 | 0.4% | Apr 15, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator wi... |
| CVE-2025-25276 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can hijack other users' devices and potentially control them. |
| CVE-2025-24850 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An attacker can export other users' plant information. |
| CVE-2025-24315 | MEDIUM | 6.9 | 0.5% | Apr 15, 2025 | Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). |
| CVE-2025-24297 | CRITICAL | 9.8 | 0.4% | Apr 15, 2025 | Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces o... |
| CVE-2025-22269 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC R... |
| CVE-2025-22268 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncann... |
| CVE-2025-22263 | HIGH | 7.1 | 0.2% | Apr 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Ga... |
| CVE-2025-32778 | CRITICAL | 9.3 | 20.0% | Apr 15, 2025 | Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screens... |
| CVE-2025-32021 | HIGH | 7.5 | 0.3% | Apr 15, 2025 | Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing componen... |
| CVE-2025-31949 | MEDIUM | 5.3 | 0.2% | Apr 15, 2025 | An authenticated attacker can obtain any plant name by knowing the plant ID. |
| CVE-2025-31941 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. |
| CVE-2025-31933 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can check the existence of usernames in the system by querying an API. |
| CVE-2025-31499 | HIGH | 8.8 | 0.6% | Apr 15, 2025 | Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFm... |
| CVE-2025-31357 | MEDIUM | 6.9 | 0.3% | Apr 15, 2025 | An unauthenticated attacker can obtain a user's plant list by knowing the username. |
| CVE-2025-30740 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte... |
| CVE-2025-30737 | MEDIUM | 5.7 | 0.2% | Apr 15, 2025 | Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The support... |
| CVE-2025-30736 | HIGH | 7.4 | 0.3% | Apr 15, 2025 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, ... |
| CVE-2025-30735 | HIGH | 8.1 | 0.3% | Apr 15, 2025 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page a... |
| CVE-2025-30733 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-... |
| CVE-2025-30732 | MEDIUM | 6.1 | 0.2% | Apr 15, 2025 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported ... |
| CVE-2025-30731 | LOW | 3.6 | 0.1% | Apr 15, 2025 | Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now