2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61310 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print ... |
| CVE-2025-61309 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Pri... |
| CVE-2025-61308 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Pri... |
| CVE-2025-61307 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Se... |
| CVE-2025-61306 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed ... |
| CVE-2025-61305 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print ... |
| CVE-2025-43992 | MEDIUM | 5.6 | 0.2% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp... |
| CVE-2025-15634 | MEDIUM | 4.3 | 0.2% | May 9, 2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie... |
| CVE-2025-15633 | MEDIUM | 6.5 | 0.2% | May 9, 2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile... |
| CVE-2025-71302 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules C... |
| CVE-2025-71301 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap... |
| CVE-2025-71300 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the de... |
| CVE-2025-71299 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the... |
| CVE-2025-71298 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv... |
| CVE-2025-71297 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi... |
| CVE-2025-71296 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg... |
| CVE-2025-69233 | MEDIUM | 5.3 | 0.4% | May 8, 2026 | Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi... |
| CVE-2025-66171 | MEDIUM | 6.5 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u... |
| CVE-2025-66170 | MEDIUM | 6.5 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti... |
| CVE-2025-67886 | MEDIUM | 6.3 | 1.0% | May 8, 2026 | Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat... |
| CVE-2025-4397 | MEDIUM | 6.8 | 0.1% | May 7, 2026 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c... |
| CVE-2025-4386 | MEDIUM | 6.8 | 0.2% | May 7, 2026 | Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ... |
| CVE-2025-67202 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul... |
| CVE-2025-68604 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr... |
| CVE-2025-66105 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now