2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63828 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password re... |
| CVE-2025-63514 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email para... |
| CVE-2025-63513 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment... |
| CVE-2025-63512 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleti... |
| CVE-2025-63258 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series rou... |
| CVE-2025-61713 | MEDIUM | 4.4 | 0.1% | Nov 18, 2025 | A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 ... |
| CVE-2025-59669 | MEDIUM | 5.5 | 0.1% | Nov 18, 2025 | A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all ve... |
| CVE-2025-56526 | MEDIUM | 6.1 | 0.4% | Nov 18, 2025 | Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted P... |
| CVE-2025-54972 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3,... |
| CVE-2025-54971 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all... |
| CVE-2025-54821 | MEDIUM | 6 | 0.1% | Nov 18, 2025 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS ... |
| CVE-2025-54660 | MEDIUM | 5.5 | 0.1% | Nov 18, 2025 | An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through ... |
| CVE-2025-53360 | MEDIUM | 4.3 | 0.3% | Nov 18, 2025 | pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the d... |
| CVE-2025-48839 | MEDIUM | 6.6 | 0.3% | Nov 18, 2025 | An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all vers... |
| CVE-2025-46775 | MEDIUM | 5.5 | 0.1% | Nov 18, 2025 | A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExt... |
| CVE-2025-46215 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, Fort... |
| CVE-2025-13082 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofin... |
| CVE-2025-13081 | MEDIUM | 5.9 | 0.2% | Nov 18, 2025 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2025-13080 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This i... |
| CVE-2025-12760 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.T... |
| CVE-2025-9977 | MEDIUM | 5.3 | 2.1% | Nov 18, 2025 | Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not saniti... |
| CVE-2025-64996 | MEDIUM | 4.4 | 0.1% | Nov 18, 2025 | In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates worl... |
| CVE-2025-63604 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code executi... |
| CVE-2025-63603 | MEDIUM | 6.5 | 0.8% | Nov 18, 2025 | A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) ... |
| CVE-2025-58122 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notifi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now