2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21581 | MEDIUM | 4.9 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2025-21580 | MEDIUM | 4.9 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte... |
| CVE-2025-21579 | MEDIUM | 4.9 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff... |
| CVE-2025-21578 | MEDIUM | 6.7 | 0.2% | Apr 15, 2025 | Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2... |
| CVE-2025-21577 | MEDIUM | 6.5 | 0.6% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2025-21576 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Su... |
| CVE-2025-21575 | MEDIUM | 6.5 | 0.7% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe... |
| CVE-2025-21574 | MEDIUM | 6.5 | 0.9% | Apr 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe... |
| CVE-2025-21573 | MEDIUM | 6 | 0.3% | Apr 15, 2025 | Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli... |
| CVE-2025-32439 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track chang... |
| CVE-2025-1292 | MEDIUM | 6.7 | 0.2% | Apr 15, 2025 | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacke... |
| CVE-2025-1122 | MEDIUM | 6.7 | 0.2% | Apr 15, 2025 | Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker wi... |
| CVE-2025-29213 | MEDIUM | 5.5 | 0.3% | Apr 15, 2025 | A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute a... |
| CVE-2025-24358 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior ... |
| CVE-2025-22903 | MEDIUM | 4.6 | 0.2% | Apr 15, 2025 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function ... |
| CVE-2025-3618 | MEDIUM | 5.5 | 1.4% | Apr 15, 2025 | A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify... |
| CVE-2025-33028 | MEDIUM | 6.1 | 0.5% | Apr 15, 2025 | In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. ... |
| CVE-2025-29705 | MEDIUM | 4.3 | 0.3% | Apr 15, 2025 | code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone... |
| CVE-2025-32779 | MEDIUM | 6.5 | 1.0% | Apr 15, 2025 | E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,... |
| CVE-2025-32776 | MEDIUM | 5.5 | 0.2% | Apr 15, 2025 | OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu... |
| CVE-2025-29817 | MEDIUM | 5.7 | 0.7% | Apr 15, 2025 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. |
| CVE-2025-28198 | MEDIUM | 5.9 | 0.2% | Apr 15, 2025 | A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the or... |
| CVE-2025-24949 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | In JotUrl 2.0, is possible to bypass security requirements during the password change process. |
| CVE-2025-24948 | MEDIUM | 6.5 | 0.3% | Apr 15, 2025 | In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insec... |
| CVE-2025-3523 | MEDIUM | 6.4 | 0.3% | Apr 15, 2025 | When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now