2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68270CRITICAL9.9The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, Cours...
CVE-2025-68156HIGH7.5Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E...
CVE-2025-68155HIGH7.5@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find...
CVE-2025-68154HIGH8.1systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct...
CVE-2025-68150MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2025-68146MEDIUM6.5filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO...
CVE-2025-65593HIGH8.8nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
CVE-2025-65592MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa...
CVE-2025-65591MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
CVE-2025-65590MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen...
CVE-2025-14553HIGH7Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came...
CVE-2025-68142MEDIUM5.3PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R...
CVE-2025-65589MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.
CVE-2025-65581MEDIUM5.3An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp...
CVE-2025-62864CRITICAL9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-62863CRITICAL9.8Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-52196HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t...
CVE-2025-46296MEDIUM5.4An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile...
CVE-2025-46295CRITICAL9.8Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications pass...
CVE-2025-46294MEDIUM5.3To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat...
CVE-2025-33235HIGH7NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a ...
CVE-2025-33226HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a...
CVE-2025-33225HIGH8.4NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict...
CVE-2025-33212HIGH7.8NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control...
CVE-2025-33210CRITICAL9NVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to cod...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now