2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61314HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ...
CVE-2025-61313HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr...
CVE-2025-61312HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S...
CVE-2025-61311HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se...
CVE-2025-61310MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print ...
CVE-2025-61309MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Pri...
CVE-2025-61308MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Pri...
CVE-2025-61307MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Se...
CVE-2025-61306MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed ...
CVE-2025-61305MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print ...
CVE-2025-9973HIGH7.2Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al...
CVE-2025-10470HIGH8.6The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re...
CVE-2025-8325HIGH8.8The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E...
CVE-2025-8154HIGH7.5In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida...
CVE-2025-43992MEDIUM5.6Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp...
CVE-2025-10908HIGH7.3Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic...
CVE-2025-14179CRITICAL9.8In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird ...
CVE-2025-15634MEDIUM4.3A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie...
CVE-2025-15633MEDIUM6.5An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile...
CVE-2025-67486HIGH7.2Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions ...
CVE-2025-71302MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules C...
CVE-2025-71301MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap...
CVE-2025-71300MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the de...
CVE-2025-71299MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the...
CVE-2025-71298MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now