2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-14303HIGH7Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not prop...
CVE-2025-14302HIGH7Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not...
CVE-2025-53524HIGH8.4Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi...
CVE-2025-14701HIGH7.1An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated...
CVE-2025-14766HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp...
CVE-2025-14765HIGH8.8Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap ...
CVE-2025-68274HIGH7.5SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp...
CVE-2025-52582HIGH7.5An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0...
CVE-2025-8872HIGH7.1On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process...
CVE-2025-68156HIGH7.5Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E...
CVE-2025-68155HIGH7.5@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find...
CVE-2025-68154HIGH8.1systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct...
CVE-2025-65593HIGH8.8nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
CVE-2025-14553HIGH7Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came...
CVE-2025-52196HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t...
CVE-2025-33235HIGH7NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a ...
CVE-2025-33226HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a...
CVE-2025-33225HIGH8.4NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict...
CVE-2025-33212HIGH7.8NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control...
CVE-2025-68130HIGH8.5tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27...
CVE-2025-68321HIGH7.5In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocat...
CVE-2025-68320HIGH7.5In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The follow...
CVE-2025-68317HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send z...
CVE-2025-68314HIGH8.8In the Linux kernel, the following vulnerability has been resolved: drm/msm: make sure last_fence is always updated Up...
CVE-2025-68313HIGH7.1In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an is...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now