2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33203 | HIGH | 7.6 | 0.3% | Nov 25, 2025 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Ser... |
| CVE-2025-33195 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer... |
| CVE-2025-33194 | HIGH | 7.1 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i... |
| CVE-2025-33190 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ... |
| CVE-2025-33189 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A... |
| CVE-2025-33188 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro... |
| CVE-2025-33187 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to... |
| CVE-2025-13483 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass ... |
| CVE-2025-64050 | HIGH | 7.2 | 0.8% | Nov 25, 2025 | A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth... |
| CVE-2025-40890 | HIGH | 7.9 | 0.2% | Nov 25, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of... |
| CVE-2025-0248 | HIGH | 8.1 | 0.3% | Nov 25, 2025 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-... |
| CVE-2025-36134 | HIGH | 7.5 | 0.3% | Nov 25, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.... |
| CVE-2025-59371 | HIGH | 7.5 | 0.7% | Nov 25, 2025 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att... |
| CVE-2025-59370 | HIGH | 7.5 | 0.9% | Nov 25, 2025 | A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul... |
| CVE-2025-13502 | HIGH | 7.5 | 0.5% | Nov 25, 2025 | A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, lea... |
| CVE-2025-13376 | HIGH | 7.2 | 0.5% | Nov 25, 2025 | The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ... |
| CVE-2025-12003 | HIGH | 8.2 | 0.6% | Nov 25, 2025 | A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact... |
| CVE-2025-13644 | HIGH | 7.5 | 0.3% | Nov 25, 2025 | MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue a... |
| CVE-2025-12742 | HIGH | 7.5 | 0.2% | Nov 25, 2025 | A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Ter... |
| CVE-2025-13507 | HIGH | 7.1 | 0.2% | Nov 25, 2025 | Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON doc... |
| CVE-2025-13068 | HIGH | 7.2 | 0.2% | Nov 25, 2025 | The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i... |
| CVE-2025-59373 | HIGH | 8.5 | 0.1% | Nov 25, 2025 | A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can... |
| CVE-2025-9803 | HIGH | 8.8 | 0.4% | Nov 25, 2025 | lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth ... |
| CVE-2025-65951 | HIGH | 8.7 | 0.1% | Nov 25, 2025 | Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim... |
| CVE-2025-64761 | HIGH | 7.2 | 0.3% | Nov 25, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now