2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71297 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi... |
| CVE-2025-71296 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg... |
| CVE-2025-69233 | MEDIUM | 5.3 | 0.4% | May 8, 2026 | Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi... |
| CVE-2025-66467 | HIGH | 8.1 | 0.4% | May 8, 2026 | Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the... |
| CVE-2025-66172 | HIGH | 8.1 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u... |
| CVE-2025-66171 | MEDIUM | 6.5 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u... |
| CVE-2025-66170 | MEDIUM | 6.5 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti... |
| CVE-2025-69691 | CRITICAL | 9.9 | 0.5% | May 8, 2026 | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ... |
| CVE-2025-69690 | CRITICAL | 9.1 | 0.6% | May 8, 2026 | Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob... |
| CVE-2025-69599 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e... |
| CVE-2025-67888 | HIGH | 7.3 | 1.2% | May 8, 2026 | An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /... |
| CVE-2025-67887 | CRITICAL | 9.8 | 1.5% | May 8, 2026 | 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla... |
| CVE-2025-67886 | MEDIUM | 6.3 | 1.0% | May 8, 2026 | Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat... |
| CVE-2025-55449 | HIGH | 7.3 | 0.3% | May 8, 2026 | AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us... |
| CVE-2025-65122 | HIGH | 7.5 | 0.3% | May 7, 2026 | Regex Denial of Service in youtube-regex npm package through version 1.0.5. |
| CVE-2025-63704 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ... |
| CVE-2025-63703 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). |
| CVE-2025-4397 | MEDIUM | 6.8 | 0.1% | May 7, 2026 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c... |
| CVE-2025-4386 | MEDIUM | 6.8 | 0.2% | May 7, 2026 | Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ... |
| CVE-2025-67202 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul... |
| CVE-2025-63706 | CRITICAL | 9.8 | 1.5% | May 7, 2026 | NPM package next-npm-version1.0.1 is vulnerable to Command injection. |
| CVE-2025-63705 | HIGH | 8.8 | 1.2% | May 7, 2026 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. |
| CVE-2025-14341 | HIGH | 8.3 | 0.2% | May 7, 2026 | Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o... |
| CVE-2025-68604 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr... |
| CVE-2025-68060 | HIGH | 7.6 | 0.2% | May 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now