2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15634MEDIUM4.3A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie...
CVE-2025-15633MEDIUM6.5An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile...
CVE-2025-71302MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules C...
CVE-2025-71301MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap...
CVE-2025-71300MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the de...
CVE-2025-71299MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the...
CVE-2025-71298MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv...
CVE-2025-71297MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi...
CVE-2025-71296MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg...
CVE-2025-69233MEDIUM5.3Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi...
CVE-2025-66171MEDIUM6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66170MEDIUM6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti...
CVE-2025-67886MEDIUM6.3Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat...
CVE-2025-4397MEDIUM6.8Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...
CVE-2025-4386MEDIUM6.8Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ...
CVE-2025-67202MEDIUM6.1Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul...
CVE-2025-68604MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr...
CVE-2025-66105MEDIUM5.3Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorr...
CVE-2025-62127MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Log...
CVE-2025-2514MEDIUM5.3Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, ...
CVE-2025-31960MEDIUM5.3HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its repor...
CVE-2025-31984MEDIUM5.4HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-31983MEDIUM4.6HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This cou...
CVE-2025-31982MEDIUM6.5HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed direct...
CVE-2025-31978MEDIUM4.3HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now