2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-33251HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33250HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33249HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input ...
CVE-2025-33246HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause ...
CVE-2025-33245HIGH8.8NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl...
CVE-2025-33243HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro...
CVE-2025-33241HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou...
CVE-2025-33240HIGH7.8NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code i...
CVE-2025-33239HIGH7.8NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code inj...
CVE-2025-33236HIGH7.8NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A...
CVE-2025-14340HIGH7.3Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an ...
CVE-2025-13689HIGH8.8IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to s...
CVE-2025-33088HIGH7.4IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca...
CVE-2025-36379HIGH7.5IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that...
CVE-2025-36377HIGH8.8IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an...
CVE-2025-36376HIGH8.8IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an...
CVE-2025-70846HIGH7.1lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field pass...
CVE-2025-67102HIGH7.6A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to exec...
CVE-2025-32355HIGH7.9Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is ...
CVE-2025-13108HIGH7.5IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in mem...
CVE-2025-36247HIGH8.2IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vul...
CVE-2025-67905HIGH8.7Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which...
CVE-2025-70828HIGH8.8An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuratio...
CVE-2025-70397HIGH7.2jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.
CVE-2025-65753HIGH7.5An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as r...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now