2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47890 | MEDIUM | 6.1 | 0.2% | Oct 14, 2025 | An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, Fo... |
| CVE-2025-37149 | MEDIUM | 6 | 0.1% | Oct 14, 2025 | A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware. |
| CVE-2025-31514 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 al... |
| CVE-2025-31366 | MEDIUM | 6.1 | 0.4% | Oct 14, 2025 | An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS ... |
| CVE-2025-25255 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 th... |
| CVE-2025-25252 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, ... |
| CVE-2025-8428 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-62157 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Wo... |
| CVE-2025-59428 | MEDIUM | 5.4 | 0.1% | Oct 14, 2025 | EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows... |
| CVE-2025-56747 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor co... |
| CVE-2025-54892 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54891 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54889 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-27906 | MEDIUM | 5.3 | 0.3% | Oct 14, 2025 | IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using ... |
| CVE-2025-10986 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authent... |
| CVE-2025-0033 | MEDIUM | 6 | 0.2% | Oct 14, 2025 | Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initi... |
| CVE-2025-7330 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missi... |
| CVE-2025-7329 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious use... |
| CVE-2025-11718 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool th... |
| CVE-2025-11716 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnera... |
| CVE-2025-11712 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encou... |
| CVE-2025-11711 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnera... |
| CVE-2025-11498 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of... |
| CVE-2025-40774 | MEDIUM | 6.7 | 0.1% | Oct 14, 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user ... |
| CVE-2025-40773 | MEDIUM | 5.3 | 0.2% | Oct 14, 2025 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now