2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8429 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-59921 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0... |
| CVE-2025-58903 | MEDIUM | 4.9 | 0.6% | Oct 14, 2025 | An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API a... |
| CVE-2025-58325 | MEDIUM | 6.7 | 0.3% | Oct 14, 2025 | An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 t... |
| CVE-2025-58324 | MEDIUM | 4.8 | 0.3% | Oct 14, 2025 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, ... |
| CVE-2025-54973 | MEDIUM | 5.3 | 0.3% | Oct 14, 2025 | A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in... |
| CVE-2025-54893 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54822 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t... |
| CVE-2025-53845 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.... |
| CVE-2025-47890 | MEDIUM | 6.1 | 0.2% | Oct 14, 2025 | An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, Fo... |
| CVE-2025-37149 | MEDIUM | 6 | 0.1% | Oct 14, 2025 | A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware. |
| CVE-2025-31514 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 al... |
| CVE-2025-31366 | MEDIUM | 6.1 | 0.4% | Oct 14, 2025 | An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS ... |
| CVE-2025-25255 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 th... |
| CVE-2025-25252 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, ... |
| CVE-2025-8428 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-62157 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Wo... |
| CVE-2025-59428 | MEDIUM | 5.4 | 0.1% | Oct 14, 2025 | EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows... |
| CVE-2025-56747 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor co... |
| CVE-2025-54892 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54891 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54889 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-27906 | MEDIUM | 5.3 | 0.3% | Oct 14, 2025 | IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using ... |
| CVE-2025-10986 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authent... |
| CVE-2025-0033 | MEDIUM | 6 | 0.2% | Oct 14, 2025 | Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now