2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30514MEDIUM6.9Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
CVE-2025-30511MEDIUM5.4An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value while addin...
CVE-2025-30254MEDIUM6.9An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
CVE-2025-2497HIGH7.8A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerabilit...
CVE-2025-27939HIGH7.5An attacker can change registered email addresses of other users and take over arbitrary accounts.
CVE-2025-27938MEDIUM6.9Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
CVE-2025-27568MEDIUM6.9An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response ...
CVE-2025-24487MEDIUM6.9An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
CVE-2025-21588MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte...
CVE-2025-21587HIGH7.4Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2025-21586MEDIUM5.4Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-21585MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-21584MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte...
CVE-2025-21583MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte...
CVE-2025-21582MEDIUM6.1Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo...
CVE-2025-21581MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-21580MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte...
CVE-2025-21579MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff...
CVE-2025-21578MEDIUM6.7Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2...
CVE-2025-21577MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-21576MEDIUM5.4Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Su...
CVE-2025-21575MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe...
CVE-2025-21574MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe...
CVE-2025-21573MEDIUM6Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli...
CVE-2025-1656HIGH7.8A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now