2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30760MEDIUM5.4Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-30759MEDIUM6.1Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se...
CVE-2025-30758MEDIUM5.3Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions t...
CVE-2025-30756MEDIUM6.1Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Eas...
CVE-2025-30754MEDIUM4.8Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2025-30753MEDIUM6.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2025-30748MEDIUM6.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S...
CVE-2025-30747MEDIUM4.3Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S...
CVE-2025-30746MEDIUM6.1Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th...
CVE-2025-30745MEDIUM6.1Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integrat...
CVE-2025-30739MEDIUM5.5Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo...
CVE-2025-53893MEDIUM6.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52082MEDIUM6.5In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi...
CVE-2025-52081MEDIUM6.5In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the ...
CVE-2025-52080MEDIUM6.5In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the ...
CVE-2025-53622MEDIUM5.2DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver...
CVE-2025-53621MEDIUM6.9DSpace open source software is a repository application which provides durable access to digital resources. Two related ...
CVE-2025-52379MEDIUM5.4Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerabili...
CVE-2025-52378MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing at...
CVE-2025-52377MEDIUM5.4Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authentica...
CVE-2025-48795MEDIUM5.6Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which mea...
CVE-2025-33097MEDIUM5.4IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authentica...
CVE-2025-30483MEDIUM5.5Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log ...
CVE-2025-4369MEDIUM5.5The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ ...
CVE-2025-24477MEDIUM6.7A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now