2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70242HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.
CVE-2025-70227HIGH7.5Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.
CVE-2025-70129MEDIUM5.3If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generate...
CVE-2025-70128MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8....
CVE-2025-48611HIGH7.8In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead t...
CVE-2025-36227MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu...
CVE-2025-36226MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authentic...
CVE-2025-13219HIGH7.5IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information...
CVE-2025-70025MEDIUM6.1An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen gen...
CVE-2025-69615CRITICAL9.1Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n...
CVE-2025-69614CRITICAL9.4Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets...
CVE-2025-68648HIGH7.2A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer ...
CVE-2025-68482MEDIUM5.9A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu...
CVE-2025-66178HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2025-56422CRITICAL9.8A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o...
CVE-2025-56421HIGH7.5SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive informatio...
CVE-2025-55717MEDIUM4A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7...
CVE-2025-54820HIGH8.1A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiM...
CVE-2025-54659HIGH7.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability i...
CVE-2025-53706——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2025-53608MEDIUM4.8An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-49784HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-48840MEDIUM5.3An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4....
CVE-2025-48418HIGH7.2A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, F...
CVE-2025-41712MEDIUM6.5An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive infor...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now