2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-20617HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa...
CVE-2025-23083HIGH7.7With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This i...
CVE-2025-23196HIGH8.8A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject an...
CVE-2025-23195HIGH7.5An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious...
CVE-2025-21571HIGH7.3Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-21565HIGH7.5Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported ver...
CVE-2025-21564HIGH8.1Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). ...
CVE-2025-21549HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported versi...
CVE-2025-21545HIGH7.5Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported ...
CVE-2025-21532HIGH7.8Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that...
CVE-2025-21521HIGH7.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that ...
CVE-2025-21516HIGH8.1Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported v...
CVE-2025-21515HIGH8.8Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-21511HIGH7.5Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-21510HIGH7.5Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte...
CVE-2025-21506HIGH8.1Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). S...
CVE-2025-23369HIGH8.8An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowe...
CVE-2025-24458HIGH7.8In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
CVE-2025-24456HIGH8.8In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
CVE-2025-24019HIGH7.1YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated use...
CVE-2025-23994HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebu...
CVE-2025-23580HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary...
CVE-2025-23551HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in razvypp SexBundle ...
CVE-2025-23489HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Messenlehner...
CVE-2025-23477HIGH8.2Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Function...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now