2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53046MEDIUM4.9Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported ...
CVE-2025-53045MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-53044MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-53042MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-53041MEDIUM6.1Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th...
CVE-2025-53040MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-53035MEDIUM6.5Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-53034MEDIUM5.4Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-50075MEDIUM6.5Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli...
CVE-2025-50074MEDIUM4.9Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli...
CVE-2025-62249MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-61457MEDIUM6.1code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.
CVE-2025-61255MEDIUM6.1Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search pa...
CVE-2025-56802MEDIUM5.1The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files...
CVE-2025-56801MEDIUM5.1The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB ...
CVE-2025-56800MEDIUM5.1Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl...
CVE-2025-56799MEDIUM6.5Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism...
CVE-2025-8050MEDIUM6.5External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.  The vulnerability could...
CVE-2025-60790MEDIUM6.5ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is ...
CVE-2025-60427MEDIUM6.5LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can ...
CVE-2025-12031MEDIUM5.3HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the ...
CVE-2025-62763MEDIUM5Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.
CVE-2025-62605MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia...
CVE-2025-62598MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ...
CVE-2025-62597MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now