mirion has 5 CVEs on record. The busiest recent month was December 2025 with 5. The median CVSS is 8.3 (high). None have a confirmed exploitation report. The most common weakness class is CWE-732 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2025-64298High· 8.4NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs46CVE-2025-62575High· 8.3NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database46CVE-2025-61940High· 8.3NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database46CVE-2025-64642High· 8.0NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and librar…44CVE-2025-64778High· 7.3NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords40
mirion vulnerabilities
CVEs affecting mirion, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-64778High· 7.3NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords
NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.
CVE-2025-64642High· 8.0NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and librar…
NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and librar…
CVE-2025-64298High· 8.4NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs
NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory p…
CVE-2025-62575High· 8.3NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of ce…
CVE-2025-61940High· 8.3NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database
NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the unde…