2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13690 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and ... |
| CVE-2025-12704 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9... |
| CVE-2025-12697 | MEDIUM | 4.4 | 0.3% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2025-12576 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18... |
| CVE-2025-12473 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all ... |
| CVE-2025-22850 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in... |
| CVE-2025-22444 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform... |
| CVE-2025-20096 | MEDIUM | 5.9 | 0.1% | Mar 10, 2026 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ... |
| CVE-2025-20005 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv... |
| CVE-2025-66413 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking ... |
| CVE-2025-13213 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp... |
| CVE-2025-70129 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate... |
| CVE-2025-70128 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.... |
| CVE-2025-36227 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu... |
| CVE-2025-36226 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authentic... |
| CVE-2025-70025 | MEDIUM | 6.1 | 0.3% | Mar 10, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen gen... |
| CVE-2025-68482 | MEDIUM | 5.9 | 0.2% | Mar 10, 2026 | A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu... |
| CVE-2025-55717 | MEDIUM | 4 | 0.1% | Mar 10, 2026 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7... |
| CVE-2025-53608 | MEDIUM | 4.8 | 0.3% | Mar 10, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-48840 | MEDIUM | 5.3 | 0.5% | Mar 10, 2026 | An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.... |
| CVE-2025-41712 | MEDIUM | 6.5 | 0.4% | Mar 10, 2026 | An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor... |
| CVE-2025-41711 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password... |
| CVE-2025-41710 | MEDIUM | 6.5 | 0.4% | Mar 10, 2026 | An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi... |
| CVE-2025-13902 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that co... |
| CVE-2025-13901 | MEDIUM | 5.3 | 0.5% | Mar 10, 2026 | CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now