2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-33203HIGH7.6NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Ser...
CVE-2025-33195HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer...
CVE-2025-33194HIGH7.1NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i...
CVE-2025-33190HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ...
CVE-2025-33189HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A...
CVE-2025-33188HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro...
CVE-2025-33187HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to...
CVE-2025-13483HIGH8.8SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass ...
CVE-2025-64050HIGH7.2A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth...
CVE-2025-40890HIGH7.9A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of...
CVE-2025-0248HIGH8.1HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-...
CVE-2025-36134HIGH7.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1....
CVE-2025-59371HIGH7.5An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att...
CVE-2025-59370HIGH7.5A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul...
CVE-2025-13502HIGH7.5A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, lea...
CVE-2025-13376HIGH7.2The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ...
CVE-2025-12003HIGH8.2A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact...
CVE-2025-13644HIGH7.5MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue a...
CVE-2025-12742HIGH7.5A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Ter...
CVE-2025-13507HIGH7.1Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON doc...
CVE-2025-13068HIGH7.2The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i...
CVE-2025-59373HIGH8.5A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can...
CVE-2025-9803HIGH8.8lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth ...
CVE-2025-65951HIGH8.7Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim...
CVE-2025-64761HIGH7.2OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now