2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4386 | MEDIUM | 6.8 | 0.2% | May 7, 2026 | Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ... |
| CVE-2025-67202 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul... |
| CVE-2025-63706 | CRITICAL | 9.8 | 1.5% | May 7, 2026 | NPM package next-npm-version1.0.1 is vulnerable to Command injection. |
| CVE-2025-63705 | HIGH | 8.8 | 1.2% | May 7, 2026 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. |
| CVE-2025-14341 | HIGH | 8.3 | 0.2% | May 7, 2026 | Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o... |
| CVE-2025-68604 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr... |
| CVE-2025-68060 | HIGH | 7.6 | 0.2% | May 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member... |
| CVE-2025-66105 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorr... |
| CVE-2025-62127 | MEDIUM | 5.9 | 0.1% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Log... |
| CVE-2025-2514 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, ... |
| CVE-2025-1978 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage ... |
| CVE-2025-9661 | CRITICAL | 9.8 | 0.9% | May 7, 2026 | OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B... |
| CVE-2025-31974 | HIGH | 7.2 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur... |
| CVE-2025-31960 | MEDIUM | 5.3 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its repor... |
| CVE-2025-52613 | HIGH | 8.8 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated ... |
| CVE-2025-31984 | MEDIUM | 5.4 | 0.1% | May 6, 2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty... |
| CVE-2025-31983 | MEDIUM | 4.6 | 0.1% | May 6, 2026 | HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This cou... |
| CVE-2025-31982 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed direct... |
| CVE-2025-31978 | MEDIUM | 4.3 | 0.1% | May 6, 2026 | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo... |
| CVE-2025-31976 | HIGH | 7.5 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while comm... |
| CVE-2025-31975 | MEDIUM | 5.3 | 0.2% | May 6, 2026 | HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose... |
| CVE-2025-31959 | LOW | 3.5 | 0.1% | May 6, 2026 | HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co... |
| CVE-2025-31957 | MEDIUM | 5.7 | 0.1% | May 6, 2026 | HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t... |
| CVE-2025-71295 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/buffer: add alert in try_to_free_buffers() for f... |
| CVE-2025-71294 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix NULL pointer issue buffer funcs If... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now