2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20617 | HIGH | 7.2 | 1.1% | Jan 22, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa... |
| CVE-2025-23083 | HIGH | 7.7 | 0.4% | Jan 22, 2025 | With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This i... |
| CVE-2025-23196 | HIGH | 8.8 | 1.2% | Jan 21, 2025 | A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject an... |
| CVE-2025-23195 | HIGH | 7.5 | 0.7% | Jan 21, 2025 | An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious... |
| CVE-2025-21571 | HIGH | 7.3 | 0.3% | Jan 21, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a... |
| CVE-2025-21565 | HIGH | 7.5 | 0.5% | Jan 21, 2025 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported ver... |
| CVE-2025-21564 | HIGH | 8.1 | 0.5% | Jan 21, 2025 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). ... |
| CVE-2025-21549 | HIGH | 7.5 | 0.5% | Jan 21, 2025 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported versi... |
| CVE-2025-21545 | HIGH | 7.5 | 0.5% | Jan 21, 2025 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported ... |
| CVE-2025-21532 | HIGH | 7.8 | 0.3% | Jan 21, 2025 | Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that... |
| CVE-2025-21521 | HIGH | 7.5 | 1.1% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that ... |
| CVE-2025-21516 | HIGH | 8.1 | 0.5% | Jan 21, 2025 | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported v... |
| CVE-2025-21515 | HIGH | 8.8 | 0.6% | Jan 21, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte... |
| CVE-2025-21511 | HIGH | 7.5 | 0.3% | Jan 21, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte... |
| CVE-2025-21510 | HIGH | 7.5 | 0.7% | Jan 21, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte... |
| CVE-2025-21506 | HIGH | 8.1 | 0.5% | Jan 21, 2025 | Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). S... |
| CVE-2025-23369 | HIGH | 8.8 | 1.6% | Jan 21, 2025 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowe... |
| CVE-2025-24458 | HIGH | 7.8 | 0.2% | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration |
| CVE-2025-24456 | HIGH | 8.8 | 0.3% | Jan 21, 2025 | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping |
| CVE-2025-24019 | HIGH | 7.1 | 0.6% | Jan 21, 2025 | YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated use... |
| CVE-2025-23994 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebu... |
| CVE-2025-23580 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary... |
| CVE-2025-23551 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in razvypp SexBundle ... |
| CVE-2025-23489 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Messenlehner... |
| CVE-2025-23477 | HIGH | 8.2 | 0.5% | Jan 21, 2025 | Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Function... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now