2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23047 | MEDIUM | 6.5 | 0.5% | Jan 22, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-C... |
| CVE-2025-24403 | MEDIUM | 4.3 | 0.3% | Jan 22, 2025 | A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read per... |
| CVE-2025-24402 | MEDIUM | 4.3 | 0.2% | Jan 22, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attacker... |
| CVE-2025-24401 | MEDIUM | 6.8 | 0.3% | Jan 22, 2025 | Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions confi... |
| CVE-2025-24400 | MEDIUM | 4.3 | 0.3% | Jan 22, 2025 | Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during s... |
| CVE-2025-24397 | MEDIUM | 4.3 | 0.3% | Jan 22, 2025 | An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure per... |
| CVE-2025-23028 | MEDIUM | 5.3 | 0.4% | Jan 22, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerabi... |
| CVE-2025-23992 | MEDIUM | 5.9 | 0.2% | Jan 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke ... |
| CVE-2025-24027 | MEDIUM | 6.2 | 0.4% | Jan 22, 2025 | ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerabi... |
| CVE-2025-23798 | MEDIUM | 6.1 | 0.3% | Jan 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElbowRobo Mass Mes... |
| CVE-2025-23684 | MEDIUM | 4.3 | 0.4% | Jan 22, 2025 | Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-23562 | MEDIUM | 5.8 | 0.7% | Jan 22, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-... |
| CVE-2025-23486 | MEDIUM | 6.5 | 0.5% | Jan 22, 2025 | Missing Authorization vulnerability in tamlyn Database Sync database-sync allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-22980 | MEDIUM | 6.7 | 0.6% | Jan 22, 2025 | A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parame... |
| CVE-2025-0604 | MEDIUM | 5.4 | 0.6% | Jan 22, 2025 | A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without perform... |
| CVE-2025-0395 | MEDIUM | 6.2 | 0.3% | Jan 22, 2025 | When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the a... |
| CVE-2025-23237 | MEDIUM | 6.6 | 0.9% | Jan 22, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa... |
| CVE-2025-21570 | MEDIUM | 6.1 | 0.3% | Jan 21, 2025 | Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login)... |
| CVE-2025-21569 | MEDIUM | 6.6 | 0.5% | Jan 21, 2025 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). ... |
| CVE-2025-21568 | MEDIUM | 4.5 | 0.4% | Jan 21, 2025 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Secu... |
| CVE-2025-21567 | MEDIUM | 4.3 | 0.5% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions... |
| CVE-2025-21566 | MEDIUM | 6.5 | 0.7% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2025-21563 | MEDIUM | 4.3 | 0.3% | Jan 21, 2025 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Co... |
| CVE-2025-21562 | MEDIUM | 4.3 | 0.3% | Jan 21, 2025 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Co... |
| CVE-2025-21561 | MEDIUM | 5.4 | 0.3% | Jan 21, 2025 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The su... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now