2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25255 | MEDIUM | 4.3 | 0.4% | Oct 14, 2025 | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 th... |
| CVE-2025-25253 | HIGH | 7.5 | 0.1% | Oct 14, 2025 | An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, ... |
| CVE-2025-25252 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, ... |
| CVE-2025-22258 | HIGH | 7.2 | 0.5% | Oct 14, 2025 | A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0... |
| CVE-2025-11577 | HIGH | 7.6 | 0.2% | Oct 14, 2025 | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot ... |
| CVE-2025-8428 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-62157 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Wo... |
| CVE-2025-62156 | HIGH | 8.8 | 0.5% | Oct 14, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version... |
| CVE-2025-5946 | HIGH | 7.2 | 13.8% | Oct 14, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Inf... |
| CVE-2025-59428 | MEDIUM | 5.4 | 0.1% | Oct 14, 2025 | EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows... |
| CVE-2025-56747 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor co... |
| CVE-2025-54892 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54891 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-54889 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-27906 | MEDIUM | 5.3 | 0.3% | Oct 14, 2025 | IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using ... |
| CVE-2025-10986 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authent... |
| CVE-2025-10985 | HIGH | 7.2 | 21.1% | Oct 14, 2025 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a... |
| CVE-2025-10243 | HIGH | 7.2 | 21.1% | Oct 14, 2025 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a... |
| CVE-2025-10242 | HIGH | 7.2 | 21.1% | Oct 14, 2025 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a... |
| CVE-2025-0033 | MEDIUM | 6 | 0.2% | Oct 14, 2025 | Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initi... |
| CVE-2025-47856 | HIGH | 7.2 | 1.4% | Oct 14, 2025 | Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] ... |
| CVE-2025-33044 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bou... |
| CVE-2025-22833 | HIGH | 7.3 | 0.1% | Oct 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by loca... |
| CVE-2025-22832 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploita... |
| CVE-2025-22831 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploita... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now