2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57823LOW2.7A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticato...
CVE-2025-55233HIGH7.8Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2025-54838MEDIUM6.5An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacke...
CVE-2025-54353MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-54100HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unau...
CVE-2025-53949HIGH8.8An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-53679HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-46637HIGH7.3Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu...
CVE-2025-46636MEDIUM6.6Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vu...
CVE-2025-34414CRITICAL9.3Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to...
CVE-2025-34413HIGH7.1Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are...
CVE-2025-34409MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter ...
CVE-2025-34408MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter o...
CVE-2025-34407MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter o...
CVE-2025-34406MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /...
CVE-2025-34404MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope par...
CVE-2025-34403MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter...
CVE-2025-34402MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter...
CVE-2025-34401MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc paramete...
CVE-2025-34400MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo param...
CVE-2025-34399MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc param...
CVE-2025-34398MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc para...
CVE-2025-34397MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter...
CVE-2025-34396HIGH7.3MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-33214HIGH8.8NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserializatio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now