2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71297MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi...
CVE-2025-71296MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg...
CVE-2025-69233MEDIUM5.3Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi...
CVE-2025-66467HIGH8.1Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the...
CVE-2025-66172HIGH8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66171MEDIUM6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66170MEDIUM6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti...
CVE-2025-69691CRITICAL9.9Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ...
CVE-2025-69690CRITICAL9.1Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob...
CVE-2025-69599CRITICAL9.8RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e...
CVE-2025-67888HIGH7.3An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /...
CVE-2025-67887CRITICAL9.81C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla...
CVE-2025-67886MEDIUM6.3Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat...
CVE-2025-55449HIGH7.3AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us...
CVE-2025-65122HIGH7.5Regex Denial of Service in youtube-regex npm package through version 1.0.5.
CVE-2025-63704CRITICAL9.8NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ...
CVE-2025-63703CRITICAL9.8npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
CVE-2025-4397MEDIUM6.8Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...
CVE-2025-4386MEDIUM6.8Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ...
CVE-2025-67202MEDIUM6.1Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul...
CVE-2025-63706CRITICAL9.8NPM package next-npm-version1.0.1 is vulnerable to Command injection.
CVE-2025-63705HIGH8.8NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CVE-2025-14341HIGH8.3Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o...
CVE-2025-68604MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr...
CVE-2025-68060HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now