2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-35990HIGH8.8Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring ...
CVE-2025-12659HIGH7.8Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could...
CVE-2025-40947HIGH7.7A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40946HIGH8.3A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6....
CVE-2025-40833HIGH8.7The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ...
CVE-2025-65418HIGH7.5docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary...
CVE-2025-61314HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ...
CVE-2025-61313HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr...
CVE-2025-61312HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S...
CVE-2025-61311HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se...
CVE-2025-9973HIGH7.2Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al...
CVE-2025-10470HIGH8.6The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re...
CVE-2025-8325HIGH8.8The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E...
CVE-2025-8154HIGH7.5In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida...
CVE-2025-10908HIGH7.3Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic...
CVE-2025-67486HIGH7.2Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions ...
CVE-2025-66467HIGH8.1Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the...
CVE-2025-66172HIGH8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-67888HIGH7.3An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /...
CVE-2025-55449HIGH7.3AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us...
CVE-2025-65122HIGH7.5Regex Denial of Service in youtube-regex npm package through version 1.0.5.
CVE-2025-63705HIGH8.8NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CVE-2025-14341HIGH8.3Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o...
CVE-2025-68060HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member...
CVE-2025-31974HIGH7.2HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now