2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65965 | HIGH | 8.2 | 0.1% | Nov 25, 2025 | Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found i... |
| CVE-2025-12816 | HIGH | 8.6 | 0.7% | Nov 25, 2025 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated atta... |
| CVE-2025-64065 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The... |
| CVE-2025-64064 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH... |
| CVE-2025-34350 | HIGH | 8.7 | 0.9% | Nov 25, 2025 | UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do... |
| CVE-2025-64066 | HIGH | 8.6 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en... |
| CVE-2025-64062 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si... |
| CVE-2025-33205 | HIGH | 7.3 | 0.1% | Nov 25, 2025 | NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func... |
| CVE-2025-33204 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre... |
| CVE-2025-33203 | HIGH | 7.6 | 0.3% | Nov 25, 2025 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Ser... |
| CVE-2025-33195 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer... |
| CVE-2025-33194 | HIGH | 7.1 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i... |
| CVE-2025-33190 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ... |
| CVE-2025-33189 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A... |
| CVE-2025-33188 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro... |
| CVE-2025-33187 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to... |
| CVE-2025-13483 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass ... |
| CVE-2025-64050 | HIGH | 7.2 | 0.8% | Nov 25, 2025 | A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth... |
| CVE-2025-40890 | HIGH | 7.9 | 0.2% | Nov 25, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of... |
| CVE-2025-0248 | HIGH | 8.1 | 0.3% | Nov 25, 2025 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-... |
| CVE-2025-36134 | HIGH | 7.5 | 0.3% | Nov 25, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.... |
| CVE-2025-59371 | HIGH | 7.5 | 0.7% | Nov 25, 2025 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att... |
| CVE-2025-59370 | HIGH | 7.5 | 0.9% | Nov 25, 2025 | A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul... |
| CVE-2025-13502 | HIGH | 7.5 | 0.5% | Nov 25, 2025 | A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, lea... |
| CVE-2025-13376 | HIGH | 7.2 | 0.5% | Nov 25, 2025 | The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now