2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40946HIGH8.3A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6....
CVE-2025-40833HIGH8.7The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ...
CVE-2025-65418HIGH7.5docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary...
CVE-2025-65417MEDIUM6.1docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page...
CVE-2025-65416MEDIUM6.3docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
CVE-2025-65415MEDIUM5.4docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic...
CVE-2025-63750——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-21709. Reason: This record is a duplicate of CVE-2026-...
CVE-2025-61314HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ...
CVE-2025-61313HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr...
CVE-2025-61312HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S...
CVE-2025-61311HIGH7.3A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se...
CVE-2025-61310MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print ...
CVE-2025-61309MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Pri...
CVE-2025-61308MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Pri...
CVE-2025-61307MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Se...
CVE-2025-61306MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed ...
CVE-2025-61305MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print ...
CVE-2025-9973HIGH7.2Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al...
CVE-2025-10470HIGH8.6The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re...
CVE-2025-8325HIGH8.8The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E...
CVE-2025-8154HIGH7.5In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida...
CVE-2025-43992MEDIUM5.6Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp...
CVE-2025-10908HIGH7.3Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic...
CVE-2025-14179CRITICAL9.8In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird ...
CVE-2025-15634MEDIUM4.3A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now