2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40946 | HIGH | 8.3 | 0.2% | May 12, 2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.... |
| CVE-2025-40833 | HIGH | 8.7 | 0.3% | May 12, 2026 | The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. ... |
| CVE-2025-65418 | HIGH | 7.5 | 0.6% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary... |
| CVE-2025-65417 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page... |
| CVE-2025-65416 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. |
| CVE-2025-65415 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic... |
| CVE-2025-63750 | — | — | — | May 11, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-21709. Reason: This record is a duplicate of CVE-2026-... |
| CVE-2025-61314 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print ... |
| CVE-2025-61313 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr... |
| CVE-2025-61312 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S... |
| CVE-2025-61311 | HIGH | 7.3 | 0.3% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se... |
| CVE-2025-61310 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print ... |
| CVE-2025-61309 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Pri... |
| CVE-2025-61308 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Pri... |
| CVE-2025-61307 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Se... |
| CVE-2025-61306 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed ... |
| CVE-2025-61305 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print ... |
| CVE-2025-9973 | HIGH | 7.2 | 0.4% | May 11, 2026 | Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server al... |
| CVE-2025-10470 | HIGH | 8.6 | 0.3% | May 11, 2026 | The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re... |
| CVE-2025-8325 | HIGH | 8.8 | 0.2% | May 11, 2026 | The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/E... |
| CVE-2025-8154 | HIGH | 7.5 | 0.2% | May 11, 2026 | In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient valida... |
| CVE-2025-43992 | MEDIUM | 5.6 | 0.2% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp... |
| CVE-2025-10908 | HIGH | 7.3 | 0.2% | May 11, 2026 | Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic... |
| CVE-2025-14179 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird ... |
| CVE-2025-15634 | MEDIUM | 4.3 | 0.2% | May 9, 2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to vie... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now