2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59808 | MEDIUM | 6.8 | 0.2% | Dec 9, 2025 | An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, Fort... |
| CVE-2025-59719 | CRITICAL | 9.8 | 23.7% | Dec 9, 2025 | An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6... |
| CVE-2025-59718 | CRITICAL | 9.8 | 65.8% | Dec 9, 2025 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 ... |
| CVE-2025-59517 | HIGH | 7.8 | 2.2% | Dec 9, 2025 | Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59516 | HIGH | 7.8 | 2.1% | Dec 9, 2025 | Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv... |
| CVE-2025-57823 | LOW | 2.7 | 0.2% | Dec 9, 2025 | A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticato... |
| CVE-2025-55233 | HIGH | 7.8 | 0.4% | Dec 9, 2025 | Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54838 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacke... |
| CVE-2025-54353 | MEDIUM | 6.1 | 5.4% | Dec 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-54100 | HIGH | 7.8 | 1.5% | Dec 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unau... |
| CVE-2025-53949 | HIGH | 8.8 | 15.5% | Dec 9, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-53679 | HIGH | 7.2 | 10.8% | Dec 9, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-46637 | HIGH | 7.3 | 0.1% | Dec 9, 2025 | Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu... |
| CVE-2025-46636 | MEDIUM | 6.6 | 0.1% | Dec 9, 2025 | Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu... |
| CVE-2025-34414 | CRITICAL | 9.3 | 0.7% | Dec 9, 2025 | Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to... |
| CVE-2025-34413 | HIGH | 7.1 | 0.4% | Dec 9, 2025 | Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are... |
| CVE-2025-34409 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter ... |
| CVE-2025-34408 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter o... |
| CVE-2025-34407 | MEDIUM | 6.1 | 0.4% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter o... |
| CVE-2025-34406 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /... |
| CVE-2025-34404 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope par... |
| CVE-2025-34403 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter... |
| CVE-2025-34402 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter... |
| CVE-2025-34401 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc paramete... |
| CVE-2025-34400 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo param... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now