2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21494 | MEDIUM | 4.1 | 0.3% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions... |
| CVE-2025-21493 | MEDIUM | 4.4 | 0.8% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions... |
| CVE-2025-21492 | MEDIUM | 4.9 | 0.9% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2025-21491 | MEDIUM | 4.9 | 1.0% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2025-21490 | MEDIUM | 4.9 | 1.2% | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2025-21489 | MEDIUM | 6.1 | 0.2% | Jan 21, 2025 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). ... |
| CVE-2025-24461 | MEDIUM | 6.5 | 0.3% | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test... |
| CVE-2025-24460 | MEDIUM | 4.3 | 0.3% | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool |
| CVE-2025-24459 | MEDIUM | 6.1 | 2.7% | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page |
| CVE-2025-24457 | MEDIUM | 5.5 | 0.6% | Jan 21, 2025 | In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs |
| CVE-2025-24020 | MEDIUM | 6.1 | 0.3% | Jan 21, 2025 | WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` e... |
| CVE-2025-23996 | MEDIUM | 4.3 | 0.1% | Jan 21, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in AnyRoad AnyRoad anyguide allows Cross Site Request Forgery.This issue... |
| CVE-2025-22722 | MEDIUM | 4.3 | 0.2% | Jan 21, 2025 | Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Config... |
| CVE-2025-22721 | MEDIUM | 4.3 | 0.2% | Jan 21, 2025 | Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-22661 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payme... |
| CVE-2025-22276 | MEDIUM | 5.9 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enguerranws Relate... |
| CVE-2025-22267 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweaver Weaver Th... |
| CVE-2025-22150 | MEDIUM | 6.8 | 0.7% | Jan 21, 2025 | Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Ma... |
| CVE-2025-24018 | MEDIUM | 5.4 | 0.4% | Jan 21, 2025 | YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user... |
| CVE-2025-24017 | MEDIUM | 6.1 | 0.3% | Jan 21, 2025 | YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DO... |
| CVE-2025-24012 | MEDIUM | 5.4 | 0.3% | Jan 21, 2025 | Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.... |
| CVE-2025-24011 | MEDIUM | 5.3 | 1.5% | Jan 21, 2025 | Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.... |
| CVE-2025-23998 | MEDIUM | 6.1 | 0.3% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in raratheme UltraLig... |
| CVE-2025-23997 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tamara Solution Ta... |
| CVE-2025-22825 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible PD... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now