2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33194HIGH7.1NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i...
CVE-2025-33193MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of i...
CVE-2025-33192MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read...
CVE-2025-33191MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read....
CVE-2025-33190HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A ...
CVE-2025-33189HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A...
CVE-2025-33188HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware contro...
CVE-2025-33187HIGH7.8NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to...
CVE-2025-13483HIGH8.8SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass ...
CVE-2025-64061MEDIUM4.3Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access con...
CVE-2025-63729CRITICAL9An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Pr...
CVE-2025-64050HIGH7.2A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote auth...
CVE-2025-64049MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote ...
CVE-2025-60739CRITICAL9.6Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logi...
CVE-2025-40890HIGH7.9A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of...
CVE-2025-13467MEDIUM5.5A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm adminis...
CVE-2025-0248HIGH8.1HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-...
CVE-2025-36134HIGH7.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1....
CVE-2025-64693CRITICAL9.8Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Con...
CVE-2025-62691CRITICAL9.8Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HT...
CVE-2025-59485MEDIUM4.8Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili...
CVE-2025-59372MEDIUM6.9A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl...
CVE-2025-59371HIGH7.5An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att...
CVE-2025-59370HIGH7.5A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul...
CVE-2025-59369MEDIUM5.9A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now