2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15633MEDIUM6.5An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privile...
CVE-2025-67486HIGH7.2Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions ...
CVE-2025-71302MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules C...
CVE-2025-71301MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap...
CVE-2025-71300MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the de...
CVE-2025-71299MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the...
CVE-2025-71298MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madv...
CVE-2025-71297MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_confi...
CVE-2025-71296MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purg...
CVE-2025-69233MEDIUM5.3Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi...
CVE-2025-66467HIGH8.1Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which the...
CVE-2025-66172HIGH8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66171MEDIUM6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u...
CVE-2025-66170MEDIUM6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenti...
CVE-2025-69691CRITICAL9.9Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ...
CVE-2025-69690CRITICAL9.1Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob...
CVE-2025-69599CRITICAL9.8RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e...
CVE-2025-67888HIGH7.3An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /...
CVE-2025-67887CRITICAL9.81C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla...
CVE-2025-67886MEDIUM6.3Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat...
CVE-2025-55449HIGH7.3AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us...
CVE-2025-65122HIGH7.5Regex Denial of Service in youtube-regex npm package through version 1.0.5.
CVE-2025-63704CRITICAL9.8NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ...
CVE-2025-63703CRITICAL9.8npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
CVE-2025-4397MEDIUM6.8Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now