2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3320 | CRITICAL | 9.8 | 0.5% | Aug 6, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i... |
| CVE-2025-23327 | CRITICAL | 9.1 | 0.5% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o... |
| CVE-2025-23319 | CRITICAL | 9.8 | 1.5% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c... |
| CVE-2025-23318 | CRITICAL | 9.8 | 0.6% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c... |
| CVE-2025-23317 | CRITICAL | 9.8 | 1.8% | Aug 6, 2025 | NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shel... |
| CVE-2025-23311 | CRITICAL | 9.8 | 2.5% | Aug 6, 2025 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially... |
| CVE-2025-23310 | CRITICAL | 9.8 | 1.8% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer... |
| CVE-2025-22470 | CRITICAL | 9.8 | 0.7% | Aug 6, 2025 | CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous file... |
| CVE-2025-27071 | CRITICAL | 9.8 | 0.2% | Aug 6, 2025 | Memory corruption while processing specific files in Powerline Communication Firmware. |
| CVE-2025-6994 | CRITICAL | 9.8 | 0.4% | Aug 6, 2025 | The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and in... |
| CVE-2025-54617 | CRITICAL | 9.8 | 0.3% | Aug 6, 2025 | Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability c... |
| CVE-2025-54883 | CRITICAL | 9.3 | 0.3% | Aug 6, 2025 | Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be... |
| CVE-2025-54594 | CRITICAL | 9.1 | 0.4% | Aug 6, 2025 | react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/wo... |
| CVE-2025-54253 | CRITICAL | 10 | 89.8% | Aug 5, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result ... |
| CVE-2025-46658 | CRITICAL | 9.8 | 0.4% | Aug 5, 2025 | An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages. |
| CVE-2025-54874 | CRITICAL | 9.8 | 0.6% | Aug 5, 2025 | OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead... |
| CVE-2025-50707 | CRITICAL | 9.8 | 1.0% | Aug 5, 2025 | An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component |
| CVE-2025-50706 | CRITICAL | 9.8 | 1.0% | Aug 5, 2025 | An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function |
| CVE-2025-2611 | CRITICAL | 9.3 | 6.1% | Aug 5, 2025 | The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject she... |
| CVE-2025-54987 | CRITICAL | 9.8 | 16.9% | Aug 5, 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ... |
| CVE-2025-54948 | CRITICAL | 9.8 | 20.3% | Aug 5, 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ... |
| CVE-2025-54982 | CRITICAL | 9.6 | 0.4% | Aug 5, 2025 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowe... |
| CVE-2025-53417 | CRITICAL | 9.3 | 10.9% | Aug 5, 2025 | DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability |
| CVE-2025-8535 | CRITICAL | 9 | 0.4% | Aug 5, 2025 | A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects... |
| CVE-2025-54865 | CRITICAL | 9.8 | 0.4% | Aug 5, 2025 | Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now