2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26065HIGH7.3A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb...
CVE-2025-8109HIGH8.8Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read o...
CVE-2025-36607HIGH7.8Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authen...
CVE-2025-36606HIGH7.8Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An...
CVE-2025-6204HIGH8An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu...
CVE-2025-41691HIGH7.5An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime system...
CVE-2025-41659HIGH8.3A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri...
CVE-2025-20702HIGH8.8In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remo...
CVE-2025-20701HIGH8.8In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou...
CVE-2025-20700HIGH8.8In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc...
CVE-2025-8500HIGH8.8A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This iss...
CVE-2025-54955HIGH8.1OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race c...
CVE-2025-23284HIGH7.8NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack bu...
CVE-2025-23283HIGH7.8NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious ...
CVE-2025-23281HIGH7NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can...
CVE-2025-23279HIGH7NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to esc...
CVE-2025-23278HIGH7.1NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index val...
CVE-2025-23277HIGH7.3NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could ...
CVE-2025-23276HIGH7.8NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful...
CVE-2025-6754HIGH8.8The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t...
CVE-2025-7694HIGH7.5The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2025-6076HIGH8.8Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor...
CVE-2025-54796HIGH7.5Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows...
CVE-2025-54782HIGH8.8Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo...
CVE-2025-54136HIGH8.8Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now