2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54603MEDIUM6.5An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat...
CVE-2025-48813MEDIUM4.7Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
CVE-2025-47979MEDIUM5.5Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i...
CVE-2025-37148MEDIUM6.5A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote atta...
CVE-2025-37145MEDIUM4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit...
CVE-2025-37144MEDIUM4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit...
CVE-2025-37143MEDIUM4.9An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/...
CVE-2025-37142MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37141MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37140MEDIUM4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor ope...
CVE-2025-37139MEDIUM6A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot i...
CVE-2025-37138MEDIUM6.2An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Cont...
CVE-2025-37137MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37136MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-37135MEDIUM6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobili...
CVE-2025-36730MEDIUM4.6A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to ...
CVE-2025-8429MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-59921MEDIUM6.5An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0...
CVE-2025-58903MEDIUM4.9An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API a...
CVE-2025-58325MEDIUM6.7An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 t...
CVE-2025-58324MEDIUM4.8An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, ...
CVE-2025-54973MEDIUM5.3A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in...
CVE-2025-54893MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54822MEDIUM4.3An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t...
CVE-2025-53845MEDIUM6.5An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now