2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5082MEDIUM6.1The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ paramete...
CVE-2025-47295LOW3.7A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 th...
CVE-2025-47294MEDIUM5.3A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may all...
CVE-2025-46777LOW2.7A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,...
CVE-2025-27528CRITICAL9.1Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through...
CVE-2025-27526MEDIUM6.5Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through...
CVE-2025-27522MEDIUM6.5Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through...
CVE-2025-25251HIGH7.8An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 th...
CVE-2025-24473LOW3.7A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindow...
CVE-2025-22252HIGH7.2A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager v...
CVE-2025-5025MEDIUM4.8libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is n...
CVE-2025-4947MEDIUM6.5libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an I...
CVE-2025-4009CRITICAL9.3The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w...
CVE-2025-4800HIGH8.8The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati...
CVE-2025-48848Rejected reason: Not used
CVE-2025-48847Rejected reason: Not used
CVE-2025-48846Rejected reason: Not used
CVE-2025-48845Rejected reason: Not used
CVE-2025-48844Rejected reason: Not used
CVE-2025-48843Rejected reason: Not used
CVE-2025-48842Rejected reason: Not used
CVE-2025-48841Rejected reason: Not used
CVE-2025-25029MEDIUM6.5IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of ...
CVE-2025-25026MEDIUM4.3IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authent...
CVE-2025-25025MEDIUM5.3IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now