2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12659HIGH7.8Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could...
CVE-2025-40947HIGH7.7A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-40946HIGH8.3A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6....
CVE-2025-40833HIGH8.7The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ...
CVE-2025-65418HIGH7.5docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary...
CVE-2025-61314HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ...
CVE-2025-61313HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr...
CVE-2025-61312HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S...
CVE-2025-61311HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se...
CVE-2025-9973HIGH7.2Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al...
CVE-2025-10470HIGH8.6The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re...
CVE-2025-8325HIGH8.8The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E...
CVE-2025-8154HIGH7.5In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida...
CVE-2025-10908HIGH7.3Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic...
CVE-2025-67486HIGH7.2Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions ...
CVE-2025-66467HIGH8.1Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the...
CVE-2025-66172HIGH8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-67888HIGH7.3An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /...
CVE-2025-55449HIGH7.3AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us...
CVE-2025-65122HIGH7.5Regex Denial of Service in youtube-regex npm package through version 1.0.5.
CVE-2025-63705HIGH8.8NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CVE-2025-14341HIGH8.3Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o...
CVE-2025-68060HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member...
CVE-2025-31974HIGH7.2HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur...
CVE-2025-52613HIGH8.8HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now