2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15633 | MEDIUM | 6.5 | 0.2% | May 9, 2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile... |
| CVE-2025-67486 | HIGH | 7.2 | 0.9% | May 8, 2026 | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions ... |
| CVE-2025-71302 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules C... |
| CVE-2025-71301 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap... |
| CVE-2025-71300 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the de... |
| CVE-2025-71299 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the... |
| CVE-2025-71298 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv... |
| CVE-2025-71297 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi... |
| CVE-2025-71296 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg... |
| CVE-2025-69233 | MEDIUM | 5.3 | 0.4% | May 8, 2026 | Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi... |
| CVE-2025-66467 | HIGH | 8.1 | 0.4% | May 8, 2026 | Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the... |
| CVE-2025-66172 | HIGH | 8.1 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u... |
| CVE-2025-66171 | MEDIUM | 6.5 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u... |
| CVE-2025-66170 | MEDIUM | 6.5 | 0.5% | May 8, 2026 | The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti... |
| CVE-2025-69691 | CRITICAL | 9.9 | 0.5% | May 8, 2026 | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ... |
| CVE-2025-69690 | CRITICAL | 9.1 | 0.6% | May 8, 2026 | Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob... |
| CVE-2025-69599 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e... |
| CVE-2025-67888 | HIGH | 7.3 | 1.2% | May 8, 2026 | An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /... |
| CVE-2025-67887 | CRITICAL | 9.8 | 1.5% | May 8, 2026 | 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla... |
| CVE-2025-67886 | MEDIUM | 6.3 | 1.0% | May 8, 2026 | Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat... |
| CVE-2025-55449 | HIGH | 7.3 | 0.3% | May 8, 2026 | AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us... |
| CVE-2025-65122 | HIGH | 7.5 | 0.3% | May 7, 2026 | Regex Denial of Service in youtube-regex npm package through version 1.0.5. |
| CVE-2025-63704 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ... |
| CVE-2025-63703 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). |
| CVE-2025-4397 | MEDIUM | 6.8 | 0.1% | May 7, 2026 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now