2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30514 | MEDIUM | 6.9 | 0.4% | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). |
| CVE-2025-30511 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value while addin... |
| CVE-2025-30254 | MEDIUM | 6.9 | 0.4% | Apr 15, 2025 | An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username. |
| CVE-2025-2497 | HIGH | 7.8 | 0.3% | Apr 15, 2025 | A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerabilit... |
| CVE-2025-27939 | HIGH | 7.5 | 0.7% | Apr 15, 2025 | An attacker can change registered email addresses of other users and take over arbitrary accounts. |
| CVE-2025-27938 | MEDIUM | 6.9 | 0.4% | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). |
| CVE-2025-27568 | MEDIUM | 6.9 | 0.4% | Apr 15, 2025 | An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response ... |
| CVE-2025-24487 | MEDIUM | 6.9 | 0.4% | Apr 15, 2025 | An unauthenticated attacker can infer the existence of usernames in the system by querying an API. |
| CVE-2025-21588 | MEDIUM | 4.9 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte... |
| CVE-2025-21587 | HIGH | 7.4 | 0.7% | Apr 15, 2025 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2025-21586 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte... |
| CVE-2025-21585 | MEDIUM | 4.9 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2025-21584 | MEDIUM | 4.9 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte... |
| CVE-2025-21583 | MEDIUM | 4.9 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte... |
| CVE-2025-21582 | MEDIUM | 6.1 | 0.3% | Apr 15, 2025 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo... |
| CVE-2025-21581 | MEDIUM | 4.9 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2025-21580 | MEDIUM | 4.9 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte... |
| CVE-2025-21579 | MEDIUM | 4.9 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff... |
| CVE-2025-21578 | MEDIUM | 6.7 | 0.2% | Apr 15, 2025 | Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2... |
| CVE-2025-21577 | MEDIUM | 6.5 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2025-21576 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Su... |
| CVE-2025-21575 | MEDIUM | 6.5 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe... |
| CVE-2025-21574 | MEDIUM | 6.5 | 0.9% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe... |
| CVE-2025-21573 | MEDIUM | 6 | 0.3% | Apr 15, 2025 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli... |
| CVE-2025-1656 | HIGH | 7.8 | 0.2% | Apr 15, 2025 | A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vuln... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now