2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0126HIGH8.3When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to imperson...
CVE-2025-0125MEDIUM6.9An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar...
CVE-2025-0124LOW3.8An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacke...
CVE-2025-0122MEDIUM5.1A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated atta...
CVE-2025-0121MEDIUM6.8A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-pri...
CVE-2025-0120HIGH7A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices al...
CVE-2025-32809MEDIUM5.4W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus ...
CVE-2025-32808HIGH7.7W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into t...
CVE-2025-32807MEDIUM5.3A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host...
CVE-2025-29918MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A ...
CVE-2025-29917MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th...
CVE-2025-29916MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Da...
CVE-2025-29915HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th...
CVE-2025-3469NONE0Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-32700LOW2.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulne...
CVE-2025-32699LOW2.1Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39....
CVE-2025-32698LOW2.1Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera...
CVE-2025-32697NONE0Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated w...
CVE-2025-32696NONE0Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated w...
CVE-2025-23010HIGH7.2An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and...
CVE-2025-23009HIGH7.2A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attac...
CVE-2025-23008HIGH7.2An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low ...
CVE-2025-22232MEDIUM5.3Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to...
CVE-2025-24866LOW2.7Mattermost versions 9.11.x <= 9.11.8  fail to enforce proper access controls on the /api/v4/audits endpoint, allowing us...
CVE-2025-32382LOW1.8Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection de...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now