2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30756MEDIUM6.1Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Eas...
CVE-2025-30754MEDIUM4.8Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2025-30753MEDIUM6.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2025-30748MEDIUM6.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S...
CVE-2025-30747MEDIUM4.3Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S...
CVE-2025-30746MEDIUM6.1Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th...
CVE-2025-30745MEDIUM6.1Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integrat...
CVE-2025-30739MEDIUM5.5Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo...
CVE-2025-53893MEDIUM6.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52082MEDIUM6.5In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi...
CVE-2025-52081MEDIUM6.5In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the ...
CVE-2025-52080MEDIUM6.5In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the ...
CVE-2025-53622MEDIUM5.2DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver...
CVE-2025-53621MEDIUM6.9DSpace open source software is a repository application which provides durable access to digital resources. Two related ...
CVE-2025-52379MEDIUM5.4Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerabili...
CVE-2025-52378MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing at...
CVE-2025-52377MEDIUM5.4Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authentica...
CVE-2025-48795MEDIUM5.6Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which mea...
CVE-2025-33097MEDIUM5.4IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authentica...
CVE-2025-30483MEDIUM5.5Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log ...
CVE-2025-4369MEDIUM5.5The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ ...
CVE-2025-24477MEDIUM6.7A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS...
CVE-2025-7672MEDIUM4.3The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS...
CVE-2025-7367MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie...
CVE-2025-53891MEDIUM4.3The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now