2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59669 | MEDIUM | 5.5 | 0.1% | Nov 18, 2025 | A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all ve... |
| CVE-2025-58692 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi... |
| CVE-2025-58413 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO... |
| CVE-2025-58034 | HIGH | 7.2 | 54.4% | Nov 18, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-56527 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage. |
| CVE-2025-56526 | MEDIUM | 6.1 | 0.4% | Nov 18, 2025 | Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted P... |
| CVE-2025-55796 | HIGH | 7.5 | 0.5% | Nov 18, 2025 | The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflow... |
| CVE-2025-54972 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3,... |
| CVE-2025-54971 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all... |
| CVE-2025-54821 | MEDIUM | 6 | 0.1% | Nov 18, 2025 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS ... |
| CVE-2025-54660 | MEDIUM | 5.5 | 0.1% | Nov 18, 2025 | An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through ... |
| CVE-2025-53843 | HIGH | 7.5 | 0.6% | Nov 18, 2025 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO... |
| CVE-2025-53360 | MEDIUM | 4.3 | 0.3% | Nov 18, 2025 | pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the d... |
| CVE-2025-48839 | MEDIUM | 6.6 | 0.3% | Nov 18, 2025 | An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all vers... |
| CVE-2025-47761 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7... |
| CVE-2025-46776 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 t... |
| CVE-2025-46775 | MEDIUM | 5.5 | 0.1% | Nov 18, 2025 | A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExt... |
| CVE-2025-46373 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F... |
| CVE-2025-46215 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, Fort... |
| CVE-2025-34324 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The mani... |
| CVE-2025-33184 | HIGH | 7.8 | 0.4% | Nov 18, 2025 | NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod... |
| CVE-2025-33183 | HIGH | 7.8 | 0.4% | Nov 18, 2025 | NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod... |
| CVE-2025-13083 | LOW | 3.7 | 0.2% | Nov 18, 2025 | Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrec... |
| CVE-2025-13082 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofin... |
| CVE-2025-13081 | MEDIUM | 5.9 | 0.2% | Nov 18, 2025 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now