2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55263HIGH7.5HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or i...
CVE-2025-55262HIGH7.5HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensiti...
CVE-2025-55275HIGH8.1HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurren...
CVE-2025-55271HIGH8.8HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h...
CVE-2025-55265HIGH7.5HCL Aftermarket DPC is affected by File Discovery which allows attacker could exploit this issue to read sensitive files...
CVE-2025-41359HIGH7.8Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo...
CVE-2025-41368HIGH8.1Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us...
CVE-2025-15101HIGH8.8An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen...
CVE-2025-64647HIGH7.5IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2025-14974HIGH7.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR)...
CVE-2025-14915HIGH7.2IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affecte...
CVE-2025-70952HIGH7.5pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling ...
CVE-2025-70887HIGH8.8An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and th...
CVE-2025-67030HIGH8.8Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d...
CVE-2025-69358HIGH7.5Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor...
CVE-2025-69347HIGH8.6Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploit...
CVE-2025-69096HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zork...
CVE-2025-27260HIGH7.5Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability ...
CVE-2025-33254HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A success...
CVE-2025-33248HIGH7.8NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin...
CVE-2025-33247HIGH7.8NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi...
CVE-2025-33238HIGH7.5NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. ...
CVE-2025-64998HIGH7.2Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi...
CVE-2025-41660HIGH8.8A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enab...
CVE-2025-60949HIGH7.5Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now