2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61751 | HIGH | 8.1 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2025-53066 | HIGH | 7.5 | 0.6% | Oct 21, 2025 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2025-53050 | HIGH | 7.5 | 0.4% | Oct 21, 2025 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). S... |
| CVE-2025-53049 | HIGH | 8.4 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W... |
| CVE-2025-53043 | HIGH | 8.1 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version... |
| CVE-2025-53036 | HIGH | 8.6 | 0.4% | Oct 21, 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2025-52079 | HIGH | 8.8 | 0.5% | Oct 21, 2025 | The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Un... |
| CVE-2025-60507 | HIGH | 8.9 | 0.3% | Oct 21, 2025 | Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role... |
| CVE-2025-11757 | HIGH | 8.7 | 0.3% | Oct 21, 2025 | The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard ... |
| CVE-2025-62518 | HIGH | 8.1 | 0.7% | Oct 21, 2025 | astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co... |
| CVE-2025-60500 | HIGH | 7.2 | 0.5% | Oct 21, 2025 | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass... |
| CVE-2025-61220 | HIGH | 7.5 | 0.3% | Oct 21, 2025 | The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other... |
| CVE-2025-60751 | HIGH | 7.5 | 2.2% | Oct 21, 2025 | GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode. |
| CVE-2025-22166 | HIGH | 7.5 | 0.5% | Oct 21, 2025 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi... |
| CVE-2025-60344 | HIGH | 8.6 | 10.3% | Oct 21, 2025 | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker... |
| CVE-2025-9339 | HIGH | 7.1 | 0.3% | Oct 21, 2025 | SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in u... |
| CVE-2025-11151 | HIGH | 8.2 | 0.3% | Oct 21, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized ... |
| CVE-2025-10020 | HIGH | 8.8 | 4.7% | Oct 21, 2025 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability... |
| CVE-2025-9428 | HIGH | 8.8 | 25.4% | Oct 21, 2025 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u... |
| CVE-2025-10641 | HIGH | 7.1 | 0.3% | Oct 21, 2025 | All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a... |
| CVE-2025-10639 | HIGH | 8.8 | 0.9% | Oct 21, 2025 | The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC... |
| CVE-2025-11949 | HIGH | 8.7 | 0.4% | Oct 21, 2025 | EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-9133 | HIGH | 8.1 | 5.5% | Oct 21, 2025 | A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi... |
| CVE-2025-8078 | HIGH | 7.2 | 1.5% | Oct 21, 2025 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US... |
| CVE-2025-7850 | HIGH | 7.2 | 2.2% | Oct 21, 2025 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now