2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21581MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-21580MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte...
CVE-2025-21579MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are aff...
CVE-2025-21578MEDIUM6.7Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2...
CVE-2025-21577MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-21576MEDIUM5.4Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Su...
CVE-2025-21575MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe...
CVE-2025-21574MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe...
CVE-2025-21573MEDIUM6Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli...
CVE-2025-32439MEDIUM6.5pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track chang...
CVE-2025-1292MEDIUM6.7Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacke...
CVE-2025-1122MEDIUM6.7Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker wi...
CVE-2025-29213MEDIUM5.5A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute a...
CVE-2025-24358MEDIUM5.4gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior ...
CVE-2025-22903MEDIUM4.6TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function ...
CVE-2025-3618MEDIUM5.5A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify...
CVE-2025-33028MEDIUM6.1In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. ...
CVE-2025-29705MEDIUM4.3code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone...
CVE-2025-32779MEDIUM6.5E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,...
CVE-2025-32776MEDIUM5.5OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu...
CVE-2025-29817MEDIUM5.7Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2025-28198MEDIUM5.9A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the or...
CVE-2025-24949MEDIUM6.5In JotUrl 2.0, is possible to bypass security requirements during the password change process.
CVE-2025-24948MEDIUM6.5In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insec...
CVE-2025-3523MEDIUM6.4When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now