2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54658HIGH7.8An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2025-53951HIGH7.8An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For...
CVE-2025-53950MEDIUM6An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's O...
CVE-2025-46752MEDIUM4.4A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al...
CVE-2025-11839MEDIUM5.5A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf...
CVE-2025-9955MEDIUM5.7An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission res...
CVE-2025-9804MEDIUM6.5An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in ...
CVE-2025-9152CRITICAL9.8An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio...
CVE-2025-10611CRITICAL9.8Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks ...
CVE-2025-3930MEDIUM6.3Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, ...
CVE-2025-6338CRITICAL9.2There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of S...
CVE-2025-58426MEDIUM5.3desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious...
CVE-2025-58079MEDIUM5.3Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker...
CVE-2025-55072MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaS...
CVE-2025-54859MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS...
CVE-2025-54760MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS...
CVE-2025-52583MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a...
CVE-2025-24833MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary...
CVE-2025-61581HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This...
CVE-2025-58115MEDIUM6.1ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be e...
CVE-2025-58075HIGH8.1Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo...
CVE-2025-58073HIGH8.1Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo...
CVE-2025-54539CRITICAL9.8A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all...
CVE-2025-54499LOW3.7Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp...
CVE-2025-54461MEDIUM6.9ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now