2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23047MEDIUM6.5Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-C...
CVE-2025-24403MEDIUM4.3A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read per...
CVE-2025-24402MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attacker...
CVE-2025-24401MEDIUM6.8Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions confi...
CVE-2025-24400MEDIUM4.3Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during s...
CVE-2025-24397MEDIUM4.3An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure per...
CVE-2025-23028MEDIUM5.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerabi...
CVE-2025-23992MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke ...
CVE-2025-24027MEDIUM6.2ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerabi...
CVE-2025-23798MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElbowRobo Mass Mes...
CVE-2025-23684MEDIUM4.3Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Exploiting Incorrectly Configured Ac...
CVE-2025-23562MEDIUM5.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-...
CVE-2025-23486MEDIUM6.5Missing Authorization vulnerability in tamlyn Database Sync database-sync allows Exploiting Incorrectly Configured Acces...
CVE-2025-22980MEDIUM6.7A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parame...
CVE-2025-0604MEDIUM5.4A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without perform...
CVE-2025-0395MEDIUM6.2When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the a...
CVE-2025-23237MEDIUM6.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa...
CVE-2025-21570MEDIUM6.1Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login)...
CVE-2025-21569MEDIUM6.6Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). ...
CVE-2025-21568MEDIUM4.5Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Secu...
CVE-2025-21567MEDIUM4.3Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions...
CVE-2025-21566MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-21563MEDIUM4.3Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Co...
CVE-2025-21562MEDIUM4.3Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Co...
CVE-2025-21561MEDIUM5.4Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The su...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now