2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65593HIGH8.8nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
CVE-2025-65592MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa...
CVE-2025-65591MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
CVE-2025-65590MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen...
CVE-2025-14553HIGH7Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came...
CVE-2025-68142MEDIUM5.3PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R...
CVE-2025-65589MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.
CVE-2025-65581MEDIUM5.3An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp...
CVE-2025-62864CRITICAL9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-62863CRITICAL9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-52196HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t...
CVE-2025-46296MEDIUM5.4An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile...
CVE-2025-46295CRITICAL9.8Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass...
CVE-2025-46294MEDIUM5.3To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat...
CVE-2025-33235HIGH7NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a ...
CVE-2025-33226HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a...
CVE-2025-33225HIGH8.4NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict...
CVE-2025-33212HIGH7.8NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control...
CVE-2025-33210CRITICAL9NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod...
CVE-2025-68130HIGH8.5tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27...
CVE-2025-68116MEDIUM5.4FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site ...
CVE-2025-63414CRITICAL10A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to a...
CVE-2025-62862MEDIUM4.6Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-59935MEDIUM6.5GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an una...
CVE-2025-50401CRITICAL9.8Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the pa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now