2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22444MEDIUM5.6Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform...
CVE-2025-20096MEDIUM5.9Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. ...
CVE-2025-20005MEDIUM5.6Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv...
CVE-2025-66413MEDIUM6.5Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking ...
CVE-2025-13213MEDIUM5.4IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp...
CVE-2025-70129MEDIUM5.3If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate...
CVE-2025-70128MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8....
CVE-2025-36227MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu...
CVE-2025-36226MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authentic...
CVE-2025-70025MEDIUM6.1An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen gen...
CVE-2025-68482MEDIUM5.9A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu...
CVE-2025-55717MEDIUM4A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7...
CVE-2025-53608MEDIUM4.8An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-48840MEDIUM5.3An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4....
CVE-2025-41712MEDIUM6.5An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor...
CVE-2025-41711MEDIUM5.3An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password...
CVE-2025-41710MEDIUM6.5An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi...
CVE-2025-13902MEDIUM5.4CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that co...
CVE-2025-13901MEDIUM5.3CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine...
CVE-2025-36173MEDIUM6.1Affected Product(s)Version(s)InfoSphere Data Architect9.2.1
CVE-2025-36105MEDIUM4.4IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s...
CVE-2025-2399MEDIUM5.9Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri...
CVE-2025-70973MEDIUM4.8ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated...
CVE-2025-70032MEDIUM6.1An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-70033MEDIUM5.4An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now