2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21494MEDIUM4.1Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions...
CVE-2025-21493MEDIUM4.4Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions...
CVE-2025-21492MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2025-21491MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-21490MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2025-21489MEDIUM6.1Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). ...
CVE-2025-24461MEDIUM6.5In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test...
CVE-2025-24460MEDIUM4.3In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
CVE-2025-24459MEDIUM6.1In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
CVE-2025-24457MEDIUM5.5In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
CVE-2025-24020MEDIUM6.1WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` e...
CVE-2025-23996MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AnyRoad AnyRoad anyguide allows Cross Site Request Forgery.This issue...
CVE-2025-22722MEDIUM4.3Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Config...
CVE-2025-22721MEDIUM4.3Missing Authorization vulnerability in Farhan Noor ApplyOnline apply-online allows Exploiting Incorrectly Configured Acc...
CVE-2025-22661MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payme...
CVE-2025-22276MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enguerranws Relate...
CVE-2025-22267MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweaver Weaver Th...
CVE-2025-22150MEDIUM6.8Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Ma...
CVE-2025-24018MEDIUM5.4YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user...
CVE-2025-24017MEDIUM6.1YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DO...
CVE-2025-24012MEDIUM5.4Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3....
CVE-2025-24011MEDIUM5.3Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3....
CVE-2025-23998MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in raratheme UltraLig...
CVE-2025-23997MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tamara Solution Ta...
CVE-2025-22825MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible PD...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now