2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-35990 | HIGH | 8.8 | 0.2% | May 12, 2026 | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring ... |
| CVE-2025-12659 | HIGH | 7.8 | 0.2% | May 12, 2026 | Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could... |
| CVE-2025-40947 | HIGH | 7.7 | 0.4% | May 12, 2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio... |
| CVE-2025-40946 | HIGH | 8.3 | 0.2% | May 12, 2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.... |
| CVE-2025-40833 | HIGH | 8.7 | 0.3% | May 12, 2026 | The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ... |
| CVE-2025-65418 | HIGH | 7.5 | 0.6% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary... |
| CVE-2025-61314 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ... |
| CVE-2025-61313 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr... |
| CVE-2025-61312 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S... |
| CVE-2025-61311 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se... |
| CVE-2025-9973 | HIGH | 7.2 | 0.4% | May 11, 2026 | Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al... |
| CVE-2025-10470 | HIGH | 8.6 | 0.3% | May 11, 2026 | The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re... |
| CVE-2025-8325 | HIGH | 8.8 | 0.2% | May 11, 2026 | The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E... |
| CVE-2025-8154 | HIGH | 7.5 | 0.2% | May 11, 2026 | In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida... |
| CVE-2025-10908 | HIGH | 7.3 | 0.2% | May 11, 2026 | Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic... |
| CVE-2025-67486 | HIGH | 7.2 | 0.9% | May 8, 2026 | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions ... |
| CVE-2025-66467 | HIGH | 8.1 | 0.4% | May 8, 2026 | Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the... |
| CVE-2025-66172 | HIGH | 8.1 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u... |
| CVE-2025-67888 | HIGH | 7.3 | 1.2% | May 8, 2026 | An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /... |
| CVE-2025-55449 | HIGH | 7.3 | 0.3% | May 8, 2026 | AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us... |
| CVE-2025-65122 | HIGH | 7.5 | 0.3% | May 7, 2026 | Regex Denial of Service in youtube-regex npm package through version 1.0.5. |
| CVE-2025-63705 | HIGH | 8.8 | 1.2% | May 7, 2026 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. |
| CVE-2025-14341 | HIGH | 8.3 | 0.2% | May 7, 2026 | Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o... |
| CVE-2025-68060 | HIGH | 7.6 | 0.2% | May 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member... |
| CVE-2025-31974 | HIGH | 7.2 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now