2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-61751HIGH8.1Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-53066HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2025-53050HIGH7.5Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). S...
CVE-2025-53049HIGH8.4Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W...
CVE-2025-53043HIGH8.1Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version...
CVE-2025-53036HIGH8.6Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-52079HIGH8.8The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Un...
CVE-2025-60507HIGH8.9Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role...
CVE-2025-11757HIGH8.7The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard ...
CVE-2025-62518HIGH8.1astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co...
CVE-2025-60500HIGH7.2QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass...
CVE-2025-61220HIGH7.5The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other...
CVE-2025-60751HIGH7.5GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
CVE-2025-22166HIGH7.5This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi...
CVE-2025-60344HIGH8.6A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker...
CVE-2025-9339HIGH7.1SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in u...
CVE-2025-11151HIGH8.2Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized ...
CVE-2025-10020HIGH8.8Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability...
CVE-2025-9428HIGH8.8Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u...
CVE-2025-10641HIGH7.1All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a...
CVE-2025-10639HIGH8.8The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC...
CVE-2025-11949HIGH8.7EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-9133HIGH8.1A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi...
CVE-2025-8078HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US...
CVE-2025-7850HIGH7.2A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now