2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54603 | MEDIUM | 6.5 | 0.6% | Oct 14, 2025 | An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat... |
| CVE-2025-48813 | MEDIUM | 4.7 | 0.2% | Oct 14, 2025 | Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. |
| CVE-2025-47979 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i... |
| CVE-2025-37148 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta... |
| CVE-2025-37145 | MEDIUM | 4.9 | 0.4% | Oct 14, 2025 | Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit... |
| CVE-2025-37144 | MEDIUM | 4.9 | 0.4% | Oct 14, 2025 | Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit... |
| CVE-2025-37143 | MEDIUM | 4.9 | 0.3% | Oct 14, 2025 | An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/... |
| CVE-2025-37142 | MEDIUM | 4.9 | 0.3% | Oct 14, 2025 | Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope... |
| CVE-2025-37141 | MEDIUM | 4.9 | 0.3% | Oct 14, 2025 | Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope... |
| CVE-2025-37140 | MEDIUM | 4.9 | 0.3% | Oct 14, 2025 | Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope... |
| CVE-2025-37139 | MEDIUM | 6 | 0.1% | Oct 14, 2025 | A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i... |
| CVE-2025-37138 | MEDIUM | 6.2 | 0.7% | Oct 14, 2025 | An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Cont... |
| CVE-2025-37137 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili... |
| CVE-2025-37136 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili... |
| CVE-2025-37135 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili... |
| CVE-2025-36730 | MEDIUM | 4.6 | 0.2% | Oct 14, 2025 | A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to ... |
| CVE-2025-8429 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-59921 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0... |
| CVE-2025-58903 | MEDIUM | 4.9 | 0.6% | Oct 14, 2025 | An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API a... |
| CVE-2025-58325 | MEDIUM | 6.7 | 0.3% | Oct 14, 2025 | An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 t... |
| CVE-2025-58324 | MEDIUM | 4.8 | 0.3% | Oct 14, 2025 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, ... |
| CVE-2025-54973 | MEDIUM | 5.3 | 0.3% | Oct 14, 2025 | A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in... |
| CVE-2025-54893 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54822 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t... |
| CVE-2025-53845 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now