2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59808 | MEDIUM | 6.8 | 0.2% | Dec 9, 2025 | An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, Fort... |
| CVE-2025-54838 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacke... |
| CVE-2025-54353 | MEDIUM | 6.1 | 5.4% | Dec 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-46636 | MEDIUM | 6.6 | 0.1% | Dec 9, 2025 | Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu... |
| CVE-2025-34409 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter ... |
| CVE-2025-34408 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter o... |
| CVE-2025-34407 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter o... |
| CVE-2025-34406 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /... |
| CVE-2025-34404 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope par... |
| CVE-2025-34403 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter... |
| CVE-2025-34402 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter... |
| CVE-2025-34401 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc paramete... |
| CVE-2025-34400 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo param... |
| CVE-2025-34399 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc param... |
| CVE-2025-34398 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc para... |
| CVE-2025-34397 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter... |
| CVE-2025-13924 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Fo... |
| CVE-2025-65289 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router... |
| CVE-2025-65288 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and sto... |
| CVE-2025-63740 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowin... |
| CVE-2025-63739 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock Ro... |
| CVE-2025-63738 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive informatio... |
| CVE-2025-63737 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 ... |
| CVE-2025-12941 | MEDIUM | 5.7 | 0.2% | Dec 9, 2025 | Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows aut... |
| CVE-2025-9638 | MEDIUM | 4.8 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now