2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-7769HIGH8.7Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE...
CVE-2025-6634HIGH7.8A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili...
CVE-2025-6633HIGH7.8A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2025-6632HIGH7.8A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-51056HIGH8.2An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t...
CVE-2025-51055HIGH8.6Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202...
CVE-2025-47908HIGH7.5Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A...
CVE-2025-51624HIGH7.6Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.
CVE-2025-46659HIGH7.5An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT...
CVE-2025-45766HIGH7poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key...
CVE-2025-38747HIGH7.8Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio...
CVE-2025-53786HIGH8On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-sec...
CVE-2025-51532HIGH7.5Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Databa...
CVE-2025-51040HIGH7.5Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html end...
CVE-2025-50286HIGH8.1A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug...
CVE-2025-36020HIGH7.5IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission...
CVE-2025-23335HIGH7.5NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker...
CVE-2025-23334HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23333HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23331HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocati...
CVE-2025-23326HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o...
CVE-2025-23325HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled...
CVE-2025-23324HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl...
CVE-2025-23323HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl...
CVE-2025-23322HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a doub...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now