2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54771MEDIUM4.9A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because t...
CVE-2025-54770MEDIUM4.9A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (...
CVE-2025-54320MEDIUM4.3In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email ...
CVE-2025-52639MEDIUM6.5HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sen...
CVE-2025-37160MEDIUM6.5A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote at...
CVE-2025-37156MEDIUM6.8A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vu...
CVE-2025-63828MEDIUM6.1Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password re...
CVE-2025-63514MEDIUM6.1kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email para...
CVE-2025-63513MEDIUM6.5kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment...
CVE-2025-63512MEDIUM6.5kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleti...
CVE-2025-63258MEDIUM6.5A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series rou...
CVE-2025-61713MEDIUM4.4A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 ...
CVE-2025-59669MEDIUM5.5A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all ve...
CVE-2025-56526MEDIUM6.1Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted P...
CVE-2025-54972MEDIUM4.3An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3,...
CVE-2025-54971MEDIUM6.5An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all...
CVE-2025-54821MEDIUM6An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS ...
CVE-2025-54660MEDIUM5.5An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through ...
CVE-2025-53360MEDIUM4.3pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the d...
CVE-2025-48839MEDIUM6.6An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all vers...
CVE-2025-46775MEDIUM5.5A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExt...
CVE-2025-46215MEDIUM5.3An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, Fort...
CVE-2025-13082MEDIUM4.3User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofin...
CVE-2025-13081MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2025-13080MEDIUM5.3Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now