2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13690MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ...
CVE-2025-12704MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9...
CVE-2025-12697MEDIUM4.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2025-12576MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18...
CVE-2025-12473MEDIUM6.1The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all ...
CVE-2025-22850MEDIUM5.6Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in...
CVE-2025-22444MEDIUM5.6Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform...
CVE-2025-20096MEDIUM5.9Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ...
CVE-2025-20005MEDIUM5.6Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv...
CVE-2025-66413MEDIUM6.5Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking ...
CVE-2025-13213MEDIUM5.4IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp...
CVE-2025-70129MEDIUM5.3If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate...
CVE-2025-70128MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8....
CVE-2025-36227MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu...
CVE-2025-36226MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authentic...
CVE-2025-70025MEDIUM6.1An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen gen...
CVE-2025-68482MEDIUM5.9A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu...
CVE-2025-55717MEDIUM4A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7...
CVE-2025-53608MEDIUM4.8An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-48840MEDIUM5.3An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4....
CVE-2025-41712MEDIUM6.5An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor...
CVE-2025-41711MEDIUM5.3An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password...
CVE-2025-41710MEDIUM6.5An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi...
CVE-2025-13902MEDIUM5.4CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that co...
CVE-2025-13901MEDIUM5.3CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now