2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33251 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit... |
| CVE-2025-33250 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit... |
| CVE-2025-33249 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input ... |
| CVE-2025-33246 | HIGH | 7.8 | 0.9% | Feb 18, 2026 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause ... |
| CVE-2025-33245 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl... |
| CVE-2025-33243 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro... |
| CVE-2025-33241 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou... |
| CVE-2025-33240 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code i... |
| CVE-2025-33239 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code inj... |
| CVE-2025-33236 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A... |
| CVE-2025-14340 | HIGH | 7.3 | 1.0% | Feb 18, 2026 | Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an ... |
| CVE-2025-13689 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to s... |
| CVE-2025-33088 | HIGH | 7.4 | 0.1% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca... |
| CVE-2025-36379 | HIGH | 7.5 | 0.1% | Feb 17, 2026 | IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that... |
| CVE-2025-36377 | HIGH | 8.8 | 0.2% | Feb 17, 2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an... |
| CVE-2025-36376 | HIGH | 8.8 | 0.2% | Feb 17, 2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an... |
| CVE-2025-70846 | HIGH | 7.1 | 0.2% | Feb 17, 2026 | lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field pass... |
| CVE-2025-67102 | HIGH | 7.6 | 0.2% | Feb 17, 2026 | A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to exec... |
| CVE-2025-32355 | HIGH | 7.9 | 1.2% | Feb 17, 2026 | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is ... |
| CVE-2025-13108 | HIGH | 7.5 | 0.2% | Feb 17, 2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in mem... |
| CVE-2025-36247 | HIGH | 8.2 | 0.3% | Feb 17, 2026 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vul... |
| CVE-2025-67905 | HIGH | 8.7 | 0.1% | Feb 17, 2026 | Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which... |
| CVE-2025-70828 | HIGH | 8.8 | 0.5% | Feb 17, 2026 | An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuratio... |
| CVE-2025-70397 | HIGH | 7.2 | 0.3% | Feb 17, 2026 | jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter. |
| CVE-2025-65753 | HIGH | 7.5 | 0.4% | Feb 17, 2026 | An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as r... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now