2025 CVE Vulnerabilities
45,199 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51742 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the... |
| CVE-2025-12816 | HIGH | 8.6 | 0.7% | Nov 25, 2025 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated atta... |
| CVE-2025-65961 | MEDIUM | 4.8 | 0.1% | Nov 25, 2025 | Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to i... |
| CVE-2025-65960 | MEDIUM | 6.6 | 0.2% | Nov 25, 2025 | Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with... |
| CVE-2025-64067 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles... |
| CVE-2025-64065 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The... |
| CVE-2025-64064 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH... |
| CVE-2025-64063 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif... |
| CVE-2025-61168 | CRITICAL | 9.8 | 0.5% | Nov 25, 2025 | An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializin... |
| CVE-2025-61167 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c... |
| CVE-2025-34350 | HIGH | 8.7 | 0.9% | Nov 25, 2025 | UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do... |
| CVE-2025-65085 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v... |
| CVE-2025-65084 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version... |
| CVE-2025-64066 | HIGH | 8.6 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en... |
| CVE-2025-64062 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si... |
| CVE-2025-33205 | HIGH | 7.3 | 0.1% | Nov 25, 2025 | NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func... |
| CVE-2025-33204 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre... |
| CVE-2025-33203 | HIGH | 7.6 | 0.3% | Nov 25, 2025 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Ser... |
| CVE-2025-33200 | LOW | 3.3 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... |
| CVE-2025-33199 | LOW | 3.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow b... |
| CVE-2025-33198 | LOW | 3.3 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... |
| CVE-2025-33197 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereferen... |
| CVE-2025-33196 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... |
| CVE-2025-33195 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer... |
| CVE-2025-33194 | HIGH | 7.1 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now