2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-25255MEDIUM4.3An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 th...
CVE-2025-25253HIGH7.5An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, ...
CVE-2025-25252MEDIUM6.5An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, ...
CVE-2025-22258HIGH7.2A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0...
CVE-2025-11577HIGH7.6Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot ...
CVE-2025-8428MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-62157MEDIUM6.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Wo...
CVE-2025-62156HIGH8.8Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version...
CVE-2025-5946HIGH7.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Inf...
CVE-2025-59428MEDIUM5.4EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows...
CVE-2025-56747MEDIUM6.5Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor co...
CVE-2025-54892MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54891MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54889MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-27906MEDIUM5.3IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using ...
CVE-2025-10986MEDIUM5.5Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authent...
CVE-2025-10985HIGH7.2OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a...
CVE-2025-10243HIGH7.2OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a...
CVE-2025-10242HIGH7.2OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a...
CVE-2025-0033MEDIUM6Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initi...
CVE-2025-47856HIGH7.2Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] ...
CVE-2025-33044HIGH7.8APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bou...
CVE-2025-22833HIGH7.3APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by loca...
CVE-2025-22832HIGH7.8APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploita...
CVE-2025-22831HIGH7.8APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploita...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now