2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-23295HIGH7.8NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code inject...
CVE-2025-23294HIGH7.8NVIDIA WebDataset for all platforms contains a vulnerability where an attacker could execute arbitrary code with elevate...
CVE-2025-1477HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18....
CVE-2025-50614HIGH7.5A buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN_0047151c function of the c...
CVE-2025-50613HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00475e1c function of the cgite...
CVE-2025-50612HIGH7.5A buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN_004743f8 function of the c...
CVE-2025-50611HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00473154 function of the cgite...
CVE-2025-50610HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00476598 function of the cgite...
CVE-2025-50609HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the Function_00465620 of the cgitest.c...
CVE-2025-50608HIGH7.5A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgite...
CVE-2025-8941HIGH7.8A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local user...
CVE-2025-55163HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, N...
CVE-2025-54809HIGH8.8F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Sof...
CVE-2025-52585HIGH8.7When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diff...
CVE-2025-50635HIGH7.5A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_...
CVE-2025-48500HIGH7.3A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, aut...
CVE-2025-46405HIGH8.7When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management M...
CVE-2025-55154HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-54382HIGH8.8Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R...
CVE-2025-32451HIGH8.8A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A sp...
CVE-2025-8907HIGH7A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the comp...
CVE-2025-8671HIGH7.5A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architect...
CVE-2025-48989HIGH7.5Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack...
CVE-2025-54464HIGH7This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device f...
CVE-2025-8914HIGH7.5Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote at...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now