2025 CVE Vulnerabilities

45,199 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-51742CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the...
CVE-2025-12816HIGH8.6An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated atta...
CVE-2025-65961MEDIUM4.8Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to i...
CVE-2025-65960MEDIUM6.6Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with...
CVE-2025-64067MEDIUM5.3Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles...
CVE-2025-64065HIGH8.8The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The...
CVE-2025-64064HIGH8.8Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH...
CVE-2025-64063CRITICAL9.8Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif...
CVE-2025-61168CRITICAL9.8An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializin...
CVE-2025-61167MEDIUM6.5SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c...
CVE-2025-34350HIGH8.7UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do...
CVE-2025-65085CRITICAL9.8A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v...
CVE-2025-65084CRITICAL9.8An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version...
CVE-2025-64066HIGH8.6Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en...
CVE-2025-64062HIGH8.8The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si...
CVE-2025-33205HIGH7.3NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func...
CVE-2025-33204HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre...
CVE-2025-33203HIGH7.6NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Ser...
CVE-2025-33200LOW3.3NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-33199LOW3.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow b...
CVE-2025-33198LOW3.3NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-33197MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereferen...
CVE-2025-33196MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-33195HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer...
CVE-2025-33194HIGH7.1NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now