2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65965HIGH8.2Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found i...
CVE-2025-12816HIGH8.6An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated atta...
CVE-2025-64065HIGH8.8The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The...
CVE-2025-64064HIGH8.8Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH...
CVE-2025-34350HIGH8.7UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do...
CVE-2025-64066HIGH8.6Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en...
CVE-2025-64062HIGH8.8The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si...
CVE-2025-33205HIGH7.3NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func...
CVE-2025-33204HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre...
CVE-2025-33203HIGH7.6NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Ser...
CVE-2025-33195HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer...
CVE-2025-33194HIGH7.1NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i...
CVE-2025-33190HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ...
CVE-2025-33189HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A...
CVE-2025-33188HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro...
CVE-2025-33187HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to...
CVE-2025-13483HIGH8.8SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass ...
CVE-2025-64050HIGH7.2A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth...
CVE-2025-40890HIGH7.9A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of...
CVE-2025-0248HIGH8.1HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-...
CVE-2025-36134HIGH7.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1....
CVE-2025-59371HIGH7.5An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att...
CVE-2025-59370HIGH7.5A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul...
CVE-2025-13502HIGH7.5A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, lea...
CVE-2025-13376HIGH7.2The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now