2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30696MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected...
CVE-2025-30695MEDIUM5.5Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-30694MEDIUM5.4Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19...
CVE-2025-30693MEDIUM5.5Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-30692MEDIUM6.5Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Attachments). Supported ver...
CVE-2025-30691MEDIUM4.8Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6,...
CVE-2025-30689MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-30688MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-30687MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-30685MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are...
CVE-2025-30684MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are...
CVE-2025-30683MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are...
CVE-2025-30682MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-30514MEDIUM6.9Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
CVE-2025-30511MEDIUM5.4An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value while addin...
CVE-2025-30254MEDIUM6.9An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
CVE-2025-27938MEDIUM6.9Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
CVE-2025-27568MEDIUM6.9An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response ...
CVE-2025-24487MEDIUM6.9An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
CVE-2025-21588MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte...
CVE-2025-21586MEDIUM5.4Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-21585MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-21584MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte...
CVE-2025-21583MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte...
CVE-2025-21582MEDIUM6.1Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Suppo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now