2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-47890MEDIUM6.1An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, Fo...
CVE-2025-37149MEDIUM6A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.
CVE-2025-31514MEDIUM4.3A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 al...
CVE-2025-31366MEDIUM6.1An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS ...
CVE-2025-25255MEDIUM4.3An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 th...
CVE-2025-25252MEDIUM6.5An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, ...
CVE-2025-8428MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-62157MEDIUM6.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Wo...
CVE-2025-59428MEDIUM5.4EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows...
CVE-2025-56747MEDIUM6.5Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor co...
CVE-2025-54892MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54891MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54889MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-27906MEDIUM5.3IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using ...
CVE-2025-10986MEDIUM5.5Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authent...
CVE-2025-0033MEDIUM6Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initi...
CVE-2025-7330MEDIUM6.5A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missi...
CVE-2025-7329MEDIUM4.8A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious use...
CVE-2025-11718MEDIUM6.5When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool th...
CVE-2025-11716MEDIUM6.5Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnera...
CVE-2025-11712MEDIUM6.1A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encou...
CVE-2025-11711MEDIUM6.5There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnera...
CVE-2025-11498MEDIUM6.1An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of...
CVE-2025-40774MEDIUM6.7A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user ...
CVE-2025-40773MEDIUM5.3A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now