2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33194 | HIGH | 7.1 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i... |
| CVE-2025-33193 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of i... |
| CVE-2025-33192 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read... |
| CVE-2025-33191 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read.... |
| CVE-2025-33190 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ... |
| CVE-2025-33189 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A... |
| CVE-2025-33188 | HIGH | 7.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro... |
| CVE-2025-33187 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to... |
| CVE-2025-13483 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass ... |
| CVE-2025-64061 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access con... |
| CVE-2025-63729 | CRITICAL | 9 | 0.1% | Nov 25, 2025 | An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Pr... |
| CVE-2025-64050 | HIGH | 7.2 | 0.8% | Nov 25, 2025 | A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth... |
| CVE-2025-64049 | MEDIUM | 4.8 | 0.3% | Nov 25, 2025 | A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote ... |
| CVE-2025-60739 | CRITICAL | 9.6 | 0.3% | Nov 25, 2025 | Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logi... |
| CVE-2025-40890 | HIGH | 7.9 | 0.2% | Nov 25, 2025 | A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of... |
| CVE-2025-13467 | MEDIUM | 5.5 | 0.4% | Nov 25, 2025 | A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm adminis... |
| CVE-2025-0248 | HIGH | 8.1 | 0.3% | Nov 25, 2025 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-... |
| CVE-2025-36134 | HIGH | 7.5 | 0.3% | Nov 25, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.... |
| CVE-2025-64693 | CRITICAL | 9.8 | 0.6% | Nov 25, 2025 | Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Con... |
| CVE-2025-62691 | CRITICAL | 9.8 | 0.6% | Nov 25, 2025 | Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HT... |
| CVE-2025-59485 | MEDIUM | 4.8 | 0.1% | Nov 25, 2025 | Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili... |
| CVE-2025-59372 | MEDIUM | 6.9 | 0.6% | Nov 25, 2025 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl... |
| CVE-2025-59371 | HIGH | 7.5 | 0.7% | Nov 25, 2025 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att... |
| CVE-2025-59370 | HIGH | 7.5 | 0.9% | Nov 25, 2025 | A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul... |
| CVE-2025-59369 | MEDIUM | 5.9 | 0.4% | Nov 25, 2025 | A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now