2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70128MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8....
CVE-2025-48611HIGH7.8In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t...
CVE-2025-36227MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu...
CVE-2025-36226MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authentic...
CVE-2025-13219HIGH7.5IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information...
CVE-2025-70025MEDIUM6.1An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen gen...
CVE-2025-69615CRITICAL9.1Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n...
CVE-2025-69614CRITICAL9.4Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets...
CVE-2025-68648HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer ...
CVE-2025-68482MEDIUM5.9A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu...
CVE-2025-66178HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2025-56422CRITICAL9.8A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o...
CVE-2025-56421HIGH7.5SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive informatio...
CVE-2025-55717MEDIUM4A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7...
CVE-2025-54820HIGH8.1A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiM...
CVE-2025-54659HIGH7.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i...
CVE-2025-53706Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-53608MEDIUM4.8An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-49784HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-48840MEDIUM5.3An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4....
CVE-2025-48418HIGH7.2A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F...
CVE-2025-41712MEDIUM6.5An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor...
CVE-2025-41711MEDIUM5.3An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password...
CVE-2025-41710MEDIUM6.5An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi...
CVE-2025-41709CRITICAL9.8An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now