2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59808MEDIUM6.8An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, Fort...
CVE-2025-59719CRITICAL9.8An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6...
CVE-2025-59718CRITICAL9.8A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 ...
CVE-2025-59517HIGH7.8Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-59516HIGH7.8Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv...
CVE-2025-57823LOW2.7A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticato...
CVE-2025-55233HIGH7.8Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-54838MEDIUM6.5An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacke...
CVE-2025-54353MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-54100HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unau...
CVE-2025-53949HIGH8.8An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-53679HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-46637HIGH7.3Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu...
CVE-2025-46636MEDIUM6.6Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu...
CVE-2025-34414CRITICAL9.3Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to...
CVE-2025-34413HIGH7.1Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are...
CVE-2025-34409MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter ...
CVE-2025-34408MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter o...
CVE-2025-34407MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter o...
CVE-2025-34406MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /...
CVE-2025-34404MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope par...
CVE-2025-34403MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter...
CVE-2025-34402MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter...
CVE-2025-34401MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc paramete...
CVE-2025-34400MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo param...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now