2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70128 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.... |
| CVE-2025-48611 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t... |
| CVE-2025-36227 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu... |
| CVE-2025-36226 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authentic... |
| CVE-2025-13219 | HIGH | 7.5 | 0.3% | Mar 10, 2026 | IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information... |
| CVE-2025-70025 | MEDIUM | 6.1 | 0.3% | Mar 10, 2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen gen... |
| CVE-2025-69615 | CRITICAL | 9.1 | 0.4% | Mar 10, 2026 | Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n... |
| CVE-2025-69614 | CRITICAL | 9.4 | 0.4% | Mar 10, 2026 | Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets... |
| CVE-2025-68648 | HIGH | 7.2 | 0.6% | Mar 10, 2026 | A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer ... |
| CVE-2025-68482 | MEDIUM | 5.9 | 0.2% | Mar 10, 2026 | A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu... |
| CVE-2025-66178 | HIGH | 7.2 | 1.7% | Mar 10, 2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2025-56422 | CRITICAL | 9.8 | 0.9% | Mar 10, 2026 | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o... |
| CVE-2025-56421 | HIGH | 7.5 | 0.5% | Mar 10, 2026 | SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive informatio... |
| CVE-2025-55717 | MEDIUM | 4 | 0.1% | Mar 10, 2026 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7... |
| CVE-2025-54820 | HIGH | 8.1 | 0.9% | Mar 10, 2026 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiM... |
| CVE-2025-54659 | HIGH | 7.5 | 0.5% | Mar 10, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i... |
| CVE-2025-53706 | — | — | — | Mar 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2025-53608 | MEDIUM | 4.8 | 0.3% | Mar 10, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-49784 | HIGH | 7.2 | 0.4% | Mar 10, 2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA... |
| CVE-2025-48840 | MEDIUM | 5.3 | 0.5% | Mar 10, 2026 | An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.... |
| CVE-2025-48418 | HIGH | 7.2 | 0.5% | Mar 10, 2026 | A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F... |
| CVE-2025-41712 | MEDIUM | 6.5 | 0.4% | Mar 10, 2026 | An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor... |
| CVE-2025-41711 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext password... |
| CVE-2025-41710 | MEDIUM | 6.5 | 0.4% | Mar 10, 2026 | An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server wi... |
| CVE-2025-41709 | CRITICAL | 9.8 | 2.2% | Mar 10, 2026 | An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now