2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-25004HIGH7.3Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-24990HIGH7.8Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o...
CVE-2025-24052HIGH7.8Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o...
CVE-2025-11548CRITICAL9.3A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the a...
CVE-2025-8429MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-62366LOW2.9mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr...
CVE-2025-62172HIGH8.5Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 t...
CVE-2025-59921MEDIUM6.5An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0...
CVE-2025-58903MEDIUM4.9An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API a...
CVE-2025-58325MEDIUM6.7An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 t...
CVE-2025-58324MEDIUM4.8An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, ...
CVE-2025-57741HIGH7.8An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, ...
CVE-2025-57740HIGH8.8An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, versi...
CVE-2025-57716HIGH7.3An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7....
CVE-2025-54973MEDIUM5.3A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in...
CVE-2025-54893MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54822MEDIUM4.3An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t...
CVE-2025-53845MEDIUM6.5An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4....
CVE-2025-49201CRITICAL9.8A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions,...
CVE-2025-47890MEDIUM6.1An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, Fo...
CVE-2025-46774HIGH7.8An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2...
CVE-2025-37149MEDIUM6A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.
CVE-2025-31514MEDIUM4.3A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 al...
CVE-2025-31366MEDIUM6.1An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS ...
CVE-2025-31365HIGH7.1An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now