2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65593 | HIGH | 8.8 | 0.3% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. |
| CVE-2025-65592 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa... |
| CVE-2025-65591 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. |
| CVE-2025-65590 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen... |
| CVE-2025-14553 | HIGH | 7 | 0.2% | Dec 16, 2025 | Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came... |
| CVE-2025-68142 | MEDIUM | 5.3 | 0.4% | Dec 16, 2025 | PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R... |
| CVE-2025-65589 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality. |
| CVE-2025-65581 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp... |
| CVE-2025-62864 | CRITICAL | 9.8 | 0.3% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-62863 | CRITICAL | 9.8 | 0.3% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-52196 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t... |
| CVE-2025-46296 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile... |
| CVE-2025-46295 | CRITICAL | 9.8 | 0.9% | Dec 16, 2025 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass... |
| CVE-2025-46294 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat... |
| CVE-2025-33235 | HIGH | 7 | 0.1% | Dec 16, 2025 | NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a ... |
| CVE-2025-33226 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a... |
| CVE-2025-33225 | HIGH | 8.4 | 0.3% | Dec 16, 2025 | NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict... |
| CVE-2025-33212 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control... |
| CVE-2025-33210 | CRITICAL | 9 | 0.5% | Dec 16, 2025 | NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod... |
| CVE-2025-68130 | HIGH | 8.5 | 0.4% | Dec 16, 2025 | tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27... |
| CVE-2025-68116 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site ... |
| CVE-2025-63414 | CRITICAL | 10 | 1.6% | Dec 16, 2025 | A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to a... |
| CVE-2025-62862 | MEDIUM | 4.6 | 0.1% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-59935 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an una... |
| CVE-2025-50401 | CRITICAL | 9.8 | 0.4% | Dec 16, 2025 | Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now