2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14303 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not prop... |
| CVE-2025-14302 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not... |
| CVE-2025-53524 | HIGH | 8.4 | 0.2% | Dec 17, 2025 | Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi... |
| CVE-2025-14701 | HIGH | 7.1 | 0.2% | Dec 17, 2025 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated... |
| CVE-2025-14766 | HIGH | 8.8 | 2.8% | Dec 16, 2025 | Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp... |
| CVE-2025-14765 | HIGH | 8.8 | 2.6% | Dec 16, 2025 | Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-68274 | HIGH | 7.5 | 0.5% | Dec 16, 2025 | SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp... |
| CVE-2025-52582 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0... |
| CVE-2025-8872 | HIGH | 7.1 | 0.3% | Dec 16, 2025 | On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process... |
| CVE-2025-68156 | HIGH | 7.5 | 0.4% | Dec 16, 2025 | Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E... |
| CVE-2025-68155 | HIGH | 7.5 | 0.6% | Dec 16, 2025 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find... |
| CVE-2025-68154 | HIGH | 8.1 | 12.9% | Dec 16, 2025 | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct... |
| CVE-2025-65593 | HIGH | 8.8 | 0.3% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. |
| CVE-2025-14553 | HIGH | 7 | 0.2% | Dec 16, 2025 | Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came... |
| CVE-2025-52196 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t... |
| CVE-2025-33235 | HIGH | 7 | 0.1% | Dec 16, 2025 | NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a ... |
| CVE-2025-33226 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a... |
| CVE-2025-33225 | HIGH | 8.4 | 0.3% | Dec 16, 2025 | NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict... |
| CVE-2025-33212 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control... |
| CVE-2025-68130 | HIGH | 8.5 | 0.4% | Dec 16, 2025 | tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27... |
| CVE-2025-68321 | HIGH | 7.5 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocat... |
| CVE-2025-68320 | HIGH | 7.5 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The follow... |
| CVE-2025-68317 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send z... |
| CVE-2025-68314 | HIGH | 8.8 | 0.1% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: make sure last_fence is always updated Up... |
| CVE-2025-68313 | HIGH | 7.1 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an is... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now