2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4386MEDIUM6.8Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to ...
CVE-2025-67202MEDIUM6.1Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vul...
CVE-2025-63706CRITICAL9.8NPM package next-npm-version1.0.1 is vulnerable to Command injection.
CVE-2025-63705HIGH8.8NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CVE-2025-14341HIGH8.3Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o...
CVE-2025-68604MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGr...
CVE-2025-68060HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member...
CVE-2025-66105MEDIUM5.3Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorr...
CVE-2025-62127MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Log...
CVE-2025-2514MEDIUM5.3Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, ...
CVE-2025-1978CRITICAL9.8Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage ...
CVE-2025-9661CRITICAL9.8OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B...
CVE-2025-31974HIGH7.2HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur...
CVE-2025-31960MEDIUM5.3HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its repor...
CVE-2025-52613HIGH8.8HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated ...
CVE-2025-31984MEDIUM5.4HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-31983MEDIUM4.6HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This cou...
CVE-2025-31982MEDIUM6.5HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed direct...
CVE-2025-31978MEDIUM4.3HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo...
CVE-2025-31976HIGH7.5HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while comm...
CVE-2025-31975MEDIUM5.3HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose...
CVE-2025-31959LOW3.5HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to co...
CVE-2025-31957MEDIUM5.7HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead t...
CVE-2025-71295MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/buffer: add alert in try_to_free_buffers() for f...
CVE-2025-71294MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix NULL pointer issue buffer funcs If...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now