2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-21487HIGH8.2Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great...
CVE-2025-21484HIGH8.2Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f...
CVE-2025-21482HIGH7.1Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-21481HIGH7.8Memory corruption while performing private key encryption in trusted application.
CVE-2025-21476HIGH7.8Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
CVE-2025-48868HIGH7.2Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) ...
CVE-2025-23354HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea...
CVE-2025-23353HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea...
CVE-2025-23349HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a...
CVE-2025-23348HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b...
CVE-2025-23339HIGH7.8NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based bu...
CVE-2025-23308HIGH7.8NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buff...
CVE-2025-23275HIGH7.1NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP...
CVE-2025-10906HIGH8.4A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit...
CVE-2025-48392HIGH7.5A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0...
CVE-2025-58319HIGH7.8Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att...
CVE-2025-58317HIGH7.8Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att...
CVE-2025-58473HIGH8.2An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f...
CVE-2025-57882HIGH8.2An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f...
CVE-2025-55069HIGH8.7A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the C...
CVE-2025-55038HIGH7.6An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Thro...
CVE-2025-59484HIGH8.7The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The ...
CVE-2025-59826HIGH7.6Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, pote...
CVE-2025-59822HIGH7.5Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s ...
CVE-2025-59534HIGH7.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now