2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-32923HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Tourmas...
CVE-2025-32784HIGH7.5conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. In versions prior to 2025...
CVE-2025-31360HIGH7.5Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
CVE-2025-30984HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools s...
CVE-2025-30970HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottwallick Easy ...
CVE-2025-29471HIGH8.3Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code ...
CVE-2025-27011HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-27008HIGH7.5Missing Authorization vulnerability in NotFound Unlimited Timeline unlimited-timeline allows Accessing Functionality Not...
CVE-2025-26953HIGH7.5Missing Authorization vulnerability in Crocoblock JetMenu jet-menu allows Accessing Functionality Not Properly Constrain...
CVE-2025-26908HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gurmehub Kargo Ent...
CVE-2025-26748HIGH8.1Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue ...
CVE-2025-26746HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced C...
CVE-2025-26730HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator wi...
CVE-2025-22263HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Ga...
CVE-2025-32021HIGH7.5Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing componen...
CVE-2025-31499HIGH8.8Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFm...
CVE-2025-30736HIGH7.4Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, ...
CVE-2025-30735HIGH8.1Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page a...
CVE-2025-30730HIGH7.5Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported ...
CVE-2025-30728HIGH7.5Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that ...
CVE-2025-30724HIGH7.5Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that...
CVE-2025-30716HIGH7.5Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Frame...
CVE-2025-30712HIGH8.1Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2025-30708HIGH7.5Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). ...
CVE-2025-30707HIGH7.5Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now